Railway communication network terminal access control method based on dynamic ACL
The railway communication network terminal access control method using dynamic ACL and three-level verification achieves accurate identification and risk rating of railway communication network terminals, solves the problems of imperfect identity management, unclear asset ledgers and outdated network access methods in railway communication networks, builds a security closed loop and reduces operation and maintenance costs.
Patent Information
- Application Number
- CN202610405637.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-03-31
- Publication Date
- 2026-05-15
AI Technical Summary
The railway communication network suffers from inadequate management of network access identities, unclear asset ledgers, outdated network access methods, and frequent unauthorized equipment connections, leading to network security risks and low management efficiency.
A railway communication network terminal access control method based on dynamic ACL is adopted. Through a three-level mapping model and progressive verification, the terminal is accurately identified and the risk is dynamically rated. Combined with multi-dimensional strategy fusion mapping and dual-channel architecture, the command is automatically adapted and reliably issued, thus constructing a security closed loop.
It achieves accurate identification and risk rating of terminals, solves the problems of poor compatibility of heterogeneous network devices and cumbersome manual configuration, builds a complete security closed loop from threat discovery to handling and recovery, and reduces operation and maintenance costs.
Smart Images

Figure CN122053240A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of communication network security technology, specifically relating to a railway communication network terminal access control method based on dynamic ACL. Background Technology
[0002] With the rapid development of railway communication networks, the number of terminal devices, intelligent devices, video surveillance and front-end devices in the internal network of communication sections is increasing day by day. The types of equipment are numerous, the brands are complex, and there are many maintenance units, which poses a severe challenge to the security access control of network terminals.
[0003] The current access control of railway communication network terminals mainly suffers from the following problems: First, the management of network access identity is imperfect, relying mainly on manual maintenance, which makes it difficult to accurately verify the true identity of access devices and personnel, and external devices are difficult to identify effectively, increasing the risk of network intrusion and data theft; Second, asset ledgers are unclear, IP asset management lacks refinement and systematization, network asset distribution and IP address allocation are chaotic, IP allocation conflicts occur frequently, and management efficiency is low; Third, existing network access methods are outdated, traditional 802.1X protocol, ARP spoofing, network traffic analysis and other technologies have compatibility issues with industrial control network switches, and require large-scale transformation of the existing network environment. The configuration commands of different brands of switches are inconsistent, resulting in high technical requirements for network engineers and a large workload for daily troubleshooting and maintenance; Fourth, unauthorized equipment connections occur frequently. The communication segment network is large in scale, the stations in each segment are scattered, and some are unattended, making it difficult to detect and control unauthorized equipment in a timely manner, posing significant security risks.
[0004] Therefore, there is an urgent need for a railway communication network terminal access control method that does not require modification of the existing network environment, is compatible with heterogeneous devices, and has full-process automated management and control capabilities. Summary of the Invention
[0005] To address the aforementioned problems in existing technologies, this invention provides a railway communication network terminal access control method based on dynamic ACL. It achieves accurate terminal identification and dynamic risk rating through mapping models and progressive verification, realizes automatic instruction adaptation and reliable delivery based on multi-dimensional strategy fusion mapping and dual-channel architecture, and forms a security closed loop based on closed-loop processing, achieving full control and efficient operation and maintenance with zero modifications.
[0006] The objective of this invention can be achieved through the following technical solutions: This disclosure provides a method for terminal access control in railway communication networks based on dynamic ACLs, including the following steps: S1. Network Environment Awareness and Demand Modeling: Collect information on network equipment and terminals in the railway communication section, extract access processes, control requirements and security compliance requirements for each business scenario, decompose them into atomic control indicators, and generate a list of control indicators through three-level mapping. S2. Terminal Authentication and Risk Awareness: The terminal entering the network is verified and its status is assessed through a three-level progressive verification. The risk level is determined by a comprehensive real-time network behavior assessment, and a handling strategy is output. S3. Dynamic ACL generation and automatic distribution: Based on the decision instructions and terminal status in the handling strategy, an ACL template is generated through multi-dimensional policy mapping, converted into switch instructions and distributed for execution, and the dynamic allocation and confirmation of permissions are completed. S4. Anomaly Tracing and Security Handling: Immediately block and isolate abnormal terminals upon detection, link to locate their physical location, push work orders and coordinate with external devices for handling, automatically restore permissions after anomaly resolution, and complete security closure and audit archiving.
[0007] Furthermore, the network environment perception and demand modeling includes the following steps: S11. Network Device Information Collection: Scan the entire network devices of the railway communication section using the Simple Network Management Protocol to obtain basic information about the switches; at the same time, obtain the connection relationships between network devices using the Network Topology Discovery Protocol to construct a network topology diagram. S12. Terminal access information collection: Network traffic is obtained through switch port mirroring technology. Combined with Address Resolution Protocol (ARP) monitoring and Dynamic Host Configuration Protocol (DHCP) message analysis, terminal device information accessing the network is identified, including existing access basic information and existing device fingerprint information. S13. Business Scenario Identification and Requirement Extraction: Based on the collected network device information and terminal access information, identify the types of business scenarios within the communication segment; for each business scenario, extract the corresponding access process, control requirements, and security compliance requirements. S14. Atomized decomposition of demand indicators: The extracted control requirements and security compliance requirements are decomposed into atomic control indicators. Each atomic control indicator has quantifiable parameter thresholds and executable judgment logic. S15. Demand Mapping Model Construction: The scattered, multi-source demand data is structured and organized through a three-layer mapping relationship to generate a scenario-terminal-port demand mapping model.
[0008] Furthermore, the basic information of the switch includes the device brand and model, device IP address, device operating status, port list, and port configuration parameters; The existing access basic information includes MAC address, IP address, access switch identifier, and access port number; the existing device fingerprint information includes operating system type, operating system version, hardware signature, and device serial number; The business scenarios include core data center scenarios, unattended station scenarios, and outdoor front-end equipment scenarios. The access process includes a terminal registration process, an authentication process, and a permission application process. The control requirements include authentication strength, access permissions, and audit policies. The security compliance requirements include requirements for terminal access control, boundary protection, and security auditing. The atomized control indicators include time-dimensional indicators, location-dimensional indicators, operation-type-dimensional indicators, terminal-type-dimensional indicators, and risk response-dimensional indicators; The demand mapping model includes: First-level mapping: Establish a mapping relationship between business scenarios and access terminal types, and determine the set of terminal types that are allowed to access in each scenario; Second-level mapping: Establish a mapping relationship between the access terminal type and the switch port to determine the range of switch ports that each type of terminal can access; The third level of mapping establishes a mapping relationship between atomic control indicators and port-level policies, determining the control policy parameters that should be executed for each port.
[0009] Furthermore, the terminal authentication and risk awareness include the following steps: S21. Terminal Access Triggering and Basic Information Extraction: When a terminal device accesses the network, network traffic initiated by the terminal is captured through switch port mirroring technology. Combined with Address Resolution Protocol (ARP) monitoring and Dynamic Host Configuration Protocol (DHCP) message analysis, the real-time access basic information of the terminal is extracted. At the same time, probe messages are sent to the terminal through active probing technology to obtain the terminal's real-time device fingerprint information. S22. Subject Authentication: Based on the business requirements of the access scenario, select the corresponding authentication mode for subject authentication; extract the authentication information and compare it with the pre-set legitimate subject database in the system to determine the legitimacy of the access subject's identity; if the subject authentication fails, directly trigger the blocking and isolation to terminate the subsequent verification process; if the verification passes, record the subject's identity identifier and proceed to the next level of verification. S23. Device authentication: The real-time device fingerprint information is compared with the known asset database to determine whether the access device belongs to a legitimate potential member. If the device authentication fails, it is judged as an asset impersonation risk, triggering a medium risk warning and implementing a differentiated handling strategy. If the authentication passes, the device identifier is recorded and the next level of authentication is entered. S24. Device Health Verification: Obtain the health check strategy corresponding to the terminal based on the device identifier, check the terminal's security indicators, calculate the terminal's health score using a weighted scoring method based on the check results of each security indicator, compare the health score with a preset threshold, and output the health status judgment result. S25. Verification Result Synthesis and Risk Level Assessment: The main body authentication result, device authentication result, and device health verification result are combined to form a three-level verification status vector, denoted as (V1, V2, V3), where V1, V2, and V3 represent the main body authentication result, device authentication result, and device health verification result, respectively. Combined with real-time network behavior, the risk level of the terminal is comprehensively assessed according to the preset risk assessment rules. Finally, the handling strategy is output based on the risk level and trust status.
[0010] Furthermore, the real-time access basic information includes the terminal's MAC address, IP address, access switch identifier, and access port number; The real-time device fingerprint information includes operating system type, operating system version, hardware signature, device serial number, and list of open ports; The authentication modes include IP+MAC binding authentication, account password authentication, and facial recognition authentication; The known asset database is a pre-established list of legitimate terminal devices, including multi-dimensional fingerprint information of all registered terminals, which serves as a comparison benchmark for device authentication. The security indicators include patch installation status, software compliance, service status, antivirus software running status, and firewall enabled status. The output health status determination result includes: If the health score is higher than the first threshold, the person is considered healthy. If the health score is between the first and second thresholds, it is judged as sub-healthy, triggering a low-risk warning. If the health score is below the second threshold, it is considered high-risk, triggering a medium-risk warning. The preset rules for risk assessment include: If V1=passed, V2=passed, and V3=healthy, and there are no abnormalities in network behavior, then it is assessed as low risk and the terminal is marked as trusted. If V1 = Pass, V2 = Pass, and V3 = Healthy, but there are abnormal network behaviors, it is assessed as medium risk; If V1 = Pass, V2 = Pass, and V3 = Sub-healthy, then it is assessed as low risk and the terminal is marked as sub-healthy. If V1 = Pass, V2 = Pass, and V3 = High Risk, then the risk level is assessed as medium risk, and the terminal is marked as high risk. If V1 = Pass and V2 = Fail, the risk level is assessed as medium and the terminal is marked as counterfeit risk. If V1 fails, it is assessed as a serious risk and the terminal is marked as an illegal entity. The handling strategy includes: Low-risk and trusted status: The decision instruction is for normal access. The decision instruction, terminal identifier, and trusted status are output to the next step. Low-risk and sub-healthy state: The decision instruction is to downgrade the access, output the decision instruction, terminal identifier and trust status to the next step, and push a patch repair prompt; Medium risk: The decision instruction is to restrict access. The decision instruction, terminal identifier, and trusted status are output to the next step, and an alarm notification is pushed. High risk / Severe risk: The decision instruction is to block and isolate, and output the decision instruction, terminal identifier and trusted status to the next step.
[0011] Furthermore, the dynamic ACL generation and automatic distribution include the following steps: S31. Policy Input Parameter Acquisition: Receive terminal identifier, trusted status, risk level and decision instruction; query terminal type in known asset database based on terminal identifier; match corresponding control record from control indicator list based on terminal identifier and current access port number; obtain time constraint, location constraint and permission range parameters of terminal in current scenario. Based on the decision command mapping policy parameters: if the decision command is for normal access, the authorization scope is configured according to the permission scope parameters, with no rate limit; if it is for downgraded access, the authorization scope is configured according to the isolated network segment, with a preset rate limit; if it is for restricted access, the authorization scope is configured according to the isolated network segment, with a strict rate limit; if it is for blocking and isolation, the authorization scope is empty, and all access is blocked. S32. Construction of Multi-dimensional ACL Policy Mapping Matrix: Based on the obtained terminal type, trust status, risk level, time constraint and location constraint, a mapping matrix is constructed, and the values of each dimension are mapped to the corresponding policy parameters. The policy parameters include authorization scope, access rate limit, audit requirements and authentication strength. S33. Dynamic ACL policy template generation: The multi-dimensional ACL policy mapping matrix is combined by Cartesian product, and each combination corresponds to a preset ACL policy template; the policy templates are sorted by priority, which is determined by the risk level, and under the same risk level, it is determined by the terminal status; the higher priority template overrides the conflict rules of the lower priority template. S34, ACL command conversion and adaptation: Obtain the brand, model and operating system version of the target switch by collecting the basic information of the switch; match the corresponding command format template from the built-in command template library, fill the authorization scope, access rate limit, audit requirements and authentication strength parameters in the policy template into the command format template, and generate ACL configuration commands that can be executed by the target switch; S35, Automatic ACL Command Issuance: The system employs a dual-channel architecture of in-band mirroring awareness and out-of-band command issuance to execute command issuance. For the in-band channel, network traffic information is continuously acquired through switch port mirroring to verify the actual effectiveness of the command issuance. For the out-of-band channel, the generated ACL configuration commands are issued to the corresponding switch ports through the multi-protocol management of the virtual LAN. S36. Policy Activation Confirmation and Status Synchronization: Verify that the ACL command has taken effect on the target switch port, read the ACL configuration status of the switch port via the SNMP protocol, and confirm that the rules have been correctly applied; store the generated dynamic ACL policy record in the policy log library, and associate it with the terminal identifier, timestamp, policy content, and distribution result; synchronously update the terminal's currently effective policy field in the known asset library for reference when adjusting or revoking policies in the future.
[0012] Furthermore, the terminal types include server terminals, industrial control terminals, monitoring terminals, and office terminals; the policy template includes fields for authorization scope, access rate limit, audit requirements, and authentication strength.
[0013] Furthermore, the anomaly tracing and security handling includes the following steps: S41. Abnormal Terminal Detection and Triggering: Based on the continuous risk perception mechanism, the network behavior of connected terminals is monitored in real time. When abnormal behavior is detected, the abnormal handling process is triggered. The terminal identifier, current risk level, and abnormal behavior context of the terminal are obtained. According to the risk response dimension indicators in the control indicator list, the handling strategy corresponding to the current risk level is matched. S42. Immediate blocking and isolation: Generate blocking and isolation instructions based on the handling strategy; through ACL instruction conversion and distribution, convert the blocking and isolation instructions into ACL configuration instructions executable by the target switch, and distribute them to the switch port accessed by the terminal to block all access of the abnormal terminal from the network layer; S43. Precise Location of Abnormal Terminals: Query the device information of the terminal in the known asset database based on the terminal identifier; locate the physical location of the abnormal terminal based on the terminal identifier and the current access port number, combined with the network topology diagram, including the access switch identifier, switch IP address, port number, rack number, and site name, and associate the location results with the abnormal event record; S44. Joint Response and Work Order Push: Based on the joint response strategy defined in the risk response dimension indicators of the control indicator list, execute the joint response of external security devices and push the response work order to the operation and maintenance platform. The work order content includes abnormal terminal identifier, physical location, abnormal behavior description, risk level, executed response measures and suggested handling solutions. S45. Anomaly Removal Confirmation and Policy Revocation: Continuously monitor the status of abnormal terminals, determine whether the anomaly has been removed through multi-source anomaly removal confirmation, and generate a policy revocation command after confirming that the anomaly has been removed; through the ACL command conversion and distribution mechanism, the revocation command is distributed to the corresponding switch port to delete or disable the previously distributed blocking ACL rules and restore the normal access permissions of the terminal. S46. Handling Records and Audit Archiving: Record and store the complete anomaly handling process in the policy log library, and associate it with the terminal identifier, anomaly behavior context, handling time, handling results at each stage and recovery time; synchronously update the terminal's security status field in the known asset library.
[0014] Furthermore, the linkage with the external security devices includes: Firewall linkage: Push blacklist rules to the firewall system and add the terminal's IP address or MAC address to the blacklist; Linked antivirus system: Sends virus scanning commands to the antivirus system, triggering a remote virus scan of the terminal; Link up with the situational awareness platform: Push risk intelligence to the situational awareness platform and update the threat intelligence database.
[0015] Furthermore, the multi-source anomaly exclusion confirmation method includes: The maintenance personnel marked the exception as resolved in the work order; The antivirus system reports that the virus has been removed; Continuous network behavior monitoring confirmed that the terminal behavior has returned to normal.
[0016] The beneficial effects of this invention are as follows: This invention transforms the access processes and security compliance requirements of multiple scenarios in railway communication sections into structured policy rules by constructing a three-level mapping model of scenario-terminal-port and a quantifiable list of control indicators, laying the foundation for dynamic ACL generation. It adopts a three-level progressive authentication method combined with real-time network behavior monitoring to achieve accurate identification and dynamic rating of terminal identity and risk status, solving the security blind spots of traditional single-dimensional verification. Based on a multi-dimensional policy mapping matrix and Cartesian product combination, it fuses and maps five-dimensional parameters of terminal identity, status, risk level, time, and location into fine-grained ACL policy templates. Combined with a dual-channel architecture of in-band mirror awareness and out-of-band command issuance, it achieves automatic adaptation, reliable issuance, and effectiveness verification of switch commands, solving the problems of poor compatibility of heterogeneous network devices and cumbersome manual configuration. Furthermore, through a four-level closed loop for anomaly handling, it constructs a complete security closed loop from threat discovery to handling and recovery, effectively reducing operation and maintenance costs. Attached Figure Description
[0017] To facilitate understanding by those skilled in the art, the present invention will be further described below with reference to the accompanying drawings.
[0018] Figure 1 A schematic diagram illustrating the steps of a railway communication network terminal access control method based on dynamic ACL provided in an embodiment of the present invention; Figure 2 This is a schematic diagram illustrating the steps of network environment perception and demand modeling provided in an embodiment of the present invention; Figure 3 This is a schematic diagram illustrating the steps of terminal authentication and risk perception provided in an embodiment of the present invention; Figure 4 This is a schematic diagram illustrating the steps of dynamic ACL generation and automatic distribution provided in an embodiment of the present invention; Figure 5 This is a schematic diagram illustrating the steps of anomaly tracing and security handling provided in an embodiment of the present invention. Detailed Implementation
[0019] To further illustrate the technical means and effects of the present invention in achieving its intended purpose, the following detailed description of the specific implementation methods, structures, features, and effects of the present invention, in conjunction with the accompanying drawings and preferred embodiments, is provided.
[0020] This invention provides a method for terminal access control in railway communication networks based on dynamic ACL. The method adopts a side-mounted deployment approach, with the platform deployed on the core switch side-mounted. It obtains network information through in-band channels and issues control commands through out-of-band channels, achieving full-network terminal access control without modifying the existing network architecture or affecting normal business operations.
[0021] Specifically, the present invention will be described in detail below: This embodiment provides a railway communication network terminal access control method based on dynamic ACL, such as... Figure 1 As shown, it includes the following steps: S1. Network Environment Awareness and Requirements Modeling: Collect information on network equipment and terminals in the railway communication section, extract access processes, control requirements, and security compliance needs for various business scenarios, decompose them into atomic control indicators, and generate a list of control indicators through a three-level mapping, such as... Figure 2 As shown, it includes the following steps: S11. Network Device Information Collection: Scan the entire network devices of the railway communication section using Simple Network Management Protocol (SNMP) to obtain basic information about the switches, including but not limited to: device brand and model, device IP address, device operating status, port list and port configuration parameters, etc.; at the same time, obtain the connection relationship between network devices through Network Topology Discovery Protocol, construct a network topology diagram, and record the cascading relationship between each switch and the access relationship between the switch and the terminal.
[0022] It should be noted that the basic information of the switch and the network topology diagram are used to build a known asset database, providing basic data for subsequent device authentication.
[0023] S12. Terminal Access Information Collection: Network traffic is obtained through switch port mirroring technology. Combined with Address Resolution Protocol (ARP) monitoring and Dynamic Host Configuration Protocol (DHCP) message analysis, terminal device information accessing the network is identified, including existing access basic information and existing device fingerprint information.
[0024] The existing access basic information includes MAC address, IP address, access switch identifier and access port number; the existing device fingerprint information includes operating system type, operating system version, hardware signature code and device serial number.
[0025] Specifically, network traffic on a specified port is copied to an analysis server using switch port mirroring technology to obtain terminal traffic data accessing the network. Combined with Address Resolution Protocol (ARP) monitoring, ARP request and response packets in the network are captured, and the mapping between the terminal's MAC address and IP address is extracted as basic information for existing access. Combined with Dynamic Host Configuration Protocol (DHCP) packet analysis, DHCP request and acknowledgment packets during the terminal's IP address acquisition process are captured, and the terminal's MAC address, assigned IP address, and hostname information are extracted as basic information for existing access. For dumb terminals such as industrial control equipment and monitoring equipment, feature matching and identification are performed using a dedicated IoT fingerprint database to extract the terminal's operating system type, operating system version, hardware signature, and device serial number as fingerprint information for existing devices. The fingerprint database includes default port characteristics, protocol characteristics, and vendor information characteristics of various industrial control equipment and monitoring equipment.
[0026] S13. Business Scenario Identification and Requirement Extraction: Based on the collected network device information and terminal access information, identify the types of business scenarios within the communication segment. The business scenarios include, but are not limited to, core computer room scenarios, unattended station scenarios, and outdoor front-end device scenarios. For each business scenario, extract the corresponding access process, control requirements, and security compliance requirements.
[0027] Specifically, the core computer room scenario corresponds to server terminals and network equipment terminals, the unattended station scenario corresponds to industrial control terminals and office terminals, and the outdoor front-end equipment scenario corresponds to monitoring terminals and sensor terminals.
[0028] The access process includes terminal registration, authentication, and permission application. Control requirements include authentication strength (single-factor authentication / two-factor authentication / device-level authentication), access permissions (accessible network segments / resources), and auditing policies (full audit / critical operation audit). Security compliance requirements include the relevant requirements for terminal access, boundary protection, and security auditing in the Cybersecurity Classified Protection 2.0 standard.
[0029] S14. Atomized decomposition of demand indicators: The extracted control requirements and security compliance requirements are decomposed into atomic control indicators. The atomic control indicators include time-dimensional indicators, location-dimensional indicators, operation type-dimensional indicators, terminal type-dimensional indicators, and risk response-dimensional indicators. Each atomic control indicator has quantifiable parameter thresholds and executable judgment logic.
[0030] Specifically, the time-dimensional indicators define the allowed access time window (e.g., working hours 09:00-18:00, non-working hours require approval) and access validity period (e.g., temporary access validity duration); the location-dimensional indicators define the allowed physical location range (e.g., within the core computer room, within unattended stations) and the allowed range of switch ports; the operation type-dimensional indicators define the allowed operation types (e.g., read-only operations, configuration operations, maintenance operations) and prohibited operation types; the terminal type-dimensional indicators define the access benchmark requirements for various types of terminals (office terminals, industrial control terminals, monitoring terminals); and the risk response-dimensional indicators define the corresponding handling strategies (alarms, rate limiting, isolation, blocking) for different risk levels (low, medium, high, severe). Each atomic control indicator has quantifiable parameter thresholds and executable judgment logic. For example, the time-dimensional indicator parameter threshold is "working hours 09:00-18:00," and the judgment logic is "if the current time is not within the threshold range, then trigger a non-working hour access alarm."
[0031] S15. Demand Mapping Model Construction: The scattered, multi-source demand data is structured and organized through a three-layer mapping relationship to generate a scenario-terminal-port demand mapping model.
[0032] The demand mapping model includes: First-level mapping: Establish a mapping relationship between business scenarios and access terminal types, and determine the set of terminal types that are allowed to access in each scenario; Second-level mapping: Establish a mapping relationship between the access terminal type and the switch port to determine the range of switch ports that each type of terminal can access; The third level of mapping establishes a mapping relationship between atomic control indicators and port-level policies, determining the control policy parameters that should be executed for each port.
[0033] It should be noted that the mapping model is stored in the form of a structured data table, which serves as the basic data structure for dynamic strategy generation.
[0034] S16. Generation of Control Indicator List: Based on the demand mapping model, the mapping relationships of each scenario, terminal type and port are traversed, and combined with atomic control indicators, a quantifiable control indicator list is generated; each record in the control indicator list includes scenario identifier, terminal type identifier, port identifier, time constraint, location constraint, operation type constraint, authentication strength threshold, permission range parameter and risk handling strategy parameter.
[0035] Understandably, the list of control indicators serves as the basic data structure for generating dynamic policies. In subsequent steps, the multi-dimensional ACL policy mapping matrix uses this as input to generate specific dynamic ACL configuration policies.
[0036] S2. Terminal Authentication and Risk Awareness: A three-tiered progressive authentication system verifies the identity and assesses the status of terminals entering the network. Based on real-time network behavior, a risk level is determined, and appropriate response strategies are output, such as... Figure 3 As shown, it includes the following steps: S21. Terminal Access Triggering and Basic Information Extraction: When a terminal device accesses the network, network traffic initiated by the terminal is captured through switch port mirroring technology. Combined with Address Resolution Protocol (ARP) monitoring and Dynamic Host Configuration Protocol (DHCP) message analysis, the terminal's real-time access basic information is extracted, including the terminal's MAC address, IP address, access switch identifier, and access port number. At the same time, probe messages are sent to the terminal through active probing technology to obtain the terminal's real-time device fingerprint information, including operating system type, operating system version, hardware signature, device serial number, and open port list.
[0037] Understandably, switch port mirroring technology replicates network traffic from one or more source ports on a switch to a designated destination port (mirror port) for real-time monitoring and analysis by network analysis devices (such as probe servers). Active probing technology refers to the analysis server proactively sending specially crafted probe messages to target terminals, inferring terminal attributes based on the characteristics of the terminal's response messages.
[0038] S22. Subject Authentication: Based on the business requirements of the access scenario, select the corresponding authentication mode for subject authentication; the authentication modes include IP+MAC binding authentication, account password authentication, and facial recognition authentication; extract the authentication information and compare it with the pre-set legitimate subject database in the system to determine the legitimacy of the access subject's identity; if the subject authentication fails, directly trigger blocking and isolation, terminating the subsequent verification process (issuing an ACL blocking command to the access switch); if the verification passes, record the subject's identity identifier and proceed to the next level of verification. The authentication information includes the terminal's IP address, MAC address, user account, user password, facial image, and static password.
[0039] Among them, IP+MAC binding authentication extracts the terminal's IP address and MAC address and compares them with records in a pre-set IP-MAC binding table. If they match, the verification is successful; otherwise, the verification fails. Account password authentication obtains the user's entered account and password through the terminal client software or web authentication page and compares them with the account and password in the user database. If they match, the verification is successful; otherwise, the verification fails. Face recognition authentication uses a two-factor authentication mode that compares a static password with an official face database. It captures the user's face image through the terminal camera, extracts the facial feature vector, compares it with a pre-set face database, and requires the user to enter a static password for double verification. If the verification is successful, the user's identity is recorded.
[0040] It should be noted that the service requirements for the access scenario refer to the authentication strength requirements for that scenario based on the service scenario type identified in S13 and the management indicator list generated in S16. The authentication strength (single-factor authentication / two-factor authentication) extracted from the management requirements in S13, combined with the authentication strength threshold field in the management indicator list in S16, jointly determine the authentication mode that should be adopted for the current access scenario. Specifically, the access port number collected in S21 is used to look up the management indicator list in S16 to obtain the scenario identifier corresponding to that port; the real-time device fingerprint information collected in S21 is combined with the first-level mapping (scenario → terminal type) in S15 to confirm the terminal type; and the authentication strength threshold corresponding to the scenario + terminal type is read from the management indicator list in S16. For example: Core data center scenario (server terminal) → authentication strength requirement is two-factor authentication → select "account password + face recognition" or "IP + MAC binding + account password"; Unattended station scenario (industrial control terminal) → authentication strength requirement is single-factor authentication → select "IP + MAC binding" or "account password"; Outdoor front-end device scenario (monitoring terminal) → authentication strength requirement is device-level authentication → mainly relies on device fingerprint verification, subject verification can be simplified.
[0041] The pre-set legitimate entity database includes pre-set legitimate IP-MAC mapping relationships, a user database (pre-set account passwords, user permission information), and a face database (pre-set authorized personnel facial feature vectors).
[0042] S23. Device Authentication: The real-time device fingerprint information is compared with the known asset database to determine whether the access device belongs to a legitimate potential member. If the device authentication fails, it is judged as an asset impersonation risk, triggering a medium-risk warning and implementing differentiated handling strategies (including recording abnormal logs, pushing alarm notifications, and restricting network access). If the authentication passes, the device identifier (such as asset number) is recorded and the next level of authentication is entered.
[0043] The known asset database is a pre-established list of legitimate terminal devices, including multi-dimensional fingerprint information of all registered terminals, used as a comparison benchmark for device authentication. Its data structure fields include device identifiers (asset numbers) automatically generated by the system or manually entered, MAC addresses, IP addresses, operating system fingerprints, hardware signatures, and device serial numbers collected in step S12, allowed access switches and ports displayed in the network topology in step S11 (S11 network topology + S15 mapping), and terminal types identified in the scenario in step S13.
[0044] It should be noted that determining whether an access device is a legitimate potential member includes: Perform multi-field fuzzy matching between real-time device fingerprint information and records in the known asset database: Exact match: MAC address match exactly; Feature matching: Hardware signature or serial number matching; Assisted matching: Operating system fingerprint matching; If the fingerprint match is successful, retrieve the "Allowed access switch" and "Allowed access port" fields from the matching record, and determine whether the current access port number is within the allowed range. If the port is within the allowed range, the access is approved; otherwise, the access is denied.
[0045] S24. Device Health Verification: Obtain the health check strategy corresponding to the terminal based on the device identifier; check the terminal's security indicators through client software installed on the terminal or through remote detection without a client, including patch installation status, software compliance, service status, antivirus software running status, and firewall enabling status; calculate the terminal health score using a weighted scoring method based on the check results of each security indicator, compare the health score with a preset threshold, and output the health status judgment result.
[0046] Wherein, the health score = Σ(indicator weight × indicator score), and the weight of each indicator is preset according to the importance of safety; the output health status judgment result includes: If the health score is higher than the first threshold (e.g., 85 points), the person is considered healthy. If the health score is between the first and second thresholds (e.g., 60-85 points), it is judged as sub-healthy, triggering a low-risk warning. If the health score is below the second threshold (e.g., 60 points), it is considered high-risk, triggering a medium-risk warning.
[0047] It should be noted that the health check strategy is a set of predefined health check items, check cycles, indicator weights, and threshold configurations for specific terminal types or scenarios. It originates from the terminal type dimension indicators in the atomic control indicators decomposed in S14 and related parameters in the list of quantifiable control indicators generated in S16. After verification in S23, the device identifier (asset number) is output, and the terminal type (server / industrial control / monitoring / office) of the device is queried in the known asset database. Based on the terminal type, the corresponding health check strategy is matched from the list of quantifiable control indicators in S16. For example, if the device identifier is "SRV-001", the known asset database shows the terminal type as "server", and the health check strategy for "server terminal" is matched from the control indicator list: health threshold 90 points, check items include patches, antivirus, service status, log auditing, etc.
[0048] The scores for indicators are obtained according to preset scoring rules. For example, in terms of patch installation status, 100 points are awarded if all critical patches are installed, 60 points are awarded if 1-2 critical patches are missing, and 0 points are awarded if 3 or more critical patches are missing. Other indicators are also manually set based on the indicator status.
[0049] S25. Verification Result Synthesis and Risk Level Assessment: The main body authentication result, device authentication result, and device health verification result are combined to form a three-level verification state vector, denoted as (V1, V2, V3), where V1, V2, and V3 represent the main body authentication result, device authentication result, and device health verification result, respectively. Combined with real-time network behavior, the risk level of the terminal is comprehensively assessed according to the preset risk assessment rules. The risk level includes low risk, medium risk, high risk, and severe risk. Finally, a handling strategy is output based on the risk level and trusted status.
[0050] The pre-defined rules for risk assessment include: If V1=passed, V2=passed, and V3=healthy, and there are no abnormalities in network behavior, then it is assessed as low risk and the terminal is marked as trusted. If V1=passed, V2=passed, and V3=healthy, but there are abnormal network behaviors (such as unauthorized network access, unauthorized external connections, or access during abnormal periods), it is rated as medium risk. If V1 = Pass, V2 = Pass, and V3 = Sub-healthy, then it is assessed as low risk and the terminal is marked as sub-healthy. If V1 = Pass, V2 = Pass, and V3 = High Risk, then the risk level is assessed as medium risk, and the terminal is marked as high risk. If V1 = Pass and V2 = Fail, the risk level is assessed as medium and the terminal is marked as counterfeit risk. If V1 fails, it is assessed as a serious risk, and the terminal is marked as an illegal entity.
[0051] The handling strategy includes: Low-risk and trusted state: The decision instruction is normal access, and the decision instruction, terminal identifier and trusted state are output to the next step S3; Low-risk and sub-healthy state: The decision instruction is to downgrade access (rate limit or access range restriction), output the decision instruction, terminal identifier and trust status to the next step S3, and push a patch repair prompt; Medium risk: The decision instruction is to restrict access (only allow access to the isolated network segment), output the decision instruction, terminal identifier and trusted status to the next step S3, and push an alarm notification; High risk / Severe risk: The decision instruction is to block and isolate, and output the decision instruction, terminal identifier and trusted status to the next step S3.
[0052] It should be noted that by monitoring network behavior in real time, continuous risk perception is performed on the subsequent behavior of connected terminals. Abnormal network behavior is used as a factor to adjust the risk level, identifying dynamic security risks such as unauthorized access, asset spoofing, and unauthorized network cross-connections. The risk level is dynamically adjusted based on the static Level 3 verification results. Real-time network behavior is used as a factor for level determination. Abnormal patterns, such as unauthorized network cross-connections, unauthorized external connections, and access during abnormal time periods, are identified through continuous traffic analysis of terminal network behavior characteristics after the terminal accesses the network.
[0053] S3. Dynamic ACL Generation and Automatic Deployment: Based on the decision instructions and terminal status in the handling policy, an ACL template is generated through multi-dimensional policy mapping, converted into switch instructions, and deployed for execution, completing the dynamic allocation and confirmation of permissions. Figure 4 As shown, it includes the following steps: S31. Policy Input Parameter Acquisition: Receive terminal identifier, trust status, risk level, and decision instruction; query the terminal type of the terminal in the known asset database based on the terminal identifier, including server terminal, industrial control terminal, monitoring terminal, and office terminal; match the corresponding control record from the control indicator list based on the terminal identifier and the current access port number to obtain the time constraint, location constraint, and permission range parameters of the terminal in the current scenario.
[0054] Based on the decision command mapping policy parameters: if the decision command is for normal access, the authorized scope is configured according to the permission scope parameters, with no speed limit; if it is for downgraded access, the authorized scope is configured according to the isolated network segment, with a preset speed limit (e.g., 1Mbps); if it is for restricted access, the authorized scope is configured according to the isolated network segment, with a strict speed limit (e.g., 512Kbps); if it is for blocking and isolation, the authorized scope is empty, and all access is blocked.
[0055] S32. Construction of Multi-dimensional ACL Policy Mapping Matrix: Based on the obtained terminal type, trust status, risk level, time constraint and location constraint, a mapping matrix is constructed. The values of each dimension are mapped to the corresponding policy parameters. The policy parameters include authorization scope, access rate limit, audit requirements and authentication strength.
[0056] S33. Dynamic ACL Policy Template Generation: The multi-dimensional ACL policy mapping matrix is combined using a Cartesian product, and each combination corresponds to a preset ACL policy template. The policy templates are sorted by priority, which is determined by the risk level (severe risk > high risk > medium risk > low risk), and within the same risk level, by the terminal status (illegal entity > impersonation risk > high risk > sub-health > trusted). Higher priority templates override conflict rules of lower priority templates. The generated policy template includes fields for authorization scope, access rate limit, audit requirements, and authentication strength.
[0057] S34. ACL Command Conversion and Adaptation: Obtain the brand, model, and operating system version of the target switch using the basic switch information collected in step S11; match the corresponding command format template from the built-in command template library, fill the authorization scope, access rate limit, audit requirements, and authentication strength parameters in the policy template into the command format template, and generate ACL configuration commands that can be executed by the target switch.
[0058] S35, Automatic ACL Command Issuance: Employs a dual-channel architecture of in-band mirroring awareness and out-of-band command issuance to execute command issuance. For the in-band channel, network traffic information is continuously acquired through switch port mirroring to verify the actual effectiveness of the command issuance. For the out-of-band channel, the generated ACL configuration commands are issued to the corresponding switch ports through multiple protocols of the Management Virtual Local Area Network (VLAN), including Simple Network Management Protocol (SNMP), Telnet, and Secure Shell Protocol (SSH).
[0059] It should be noted that before the ACL rules are distributed, the connectivity and protocol support of the target switch are detected by the SNMP protocol, and an available protocol is selected for distribution. After distribution, the effectiveness of the ACL rules is verified by the in-band channel (test traffic is sent to the port to check whether the traffic forwarding behavior meets the expected policy. If it does not meet the policy, it is determined that the rules have failed to take effect). If the distribution fails, a retry mechanism or alarm is triggered.
[0060] S36. Policy Activation Confirmation and Status Synchronization: Verify that the ACL command has taken effect on the target switch port, read the ACL configuration status of the switch port via the SNMP protocol, and confirm that the rules have been correctly applied; store the generated dynamic ACL policy record in the policy log library, and associate it with the terminal identifier, timestamp, policy content, and distribution result; synchronously update the current effective policy field of the terminal in the known asset library for reference when adjusting or revoking policies in the future.
[0061] S4. Anomaly Tracing and Security Handling: Upon detecting an abnormal terminal, immediately block and isolate it, coordinate to locate its physical position, push work orders and coordinate with external devices for handling, automatically restore permissions after the anomaly is resolved, completing a security loop and audit archiving. Figure 5 As shown, it includes the following steps: S41. Abnormal Terminal Detection and Triggering: Based on the continuous risk perception mechanism, the network behavior of connected terminals is monitored in real time. When abnormal behavior (including unauthorized network access, unauthorized external connections, abnormal time period access, and lateral attack) is detected, the abnormal handling process is triggered. The terminal identifier, current risk level, and abnormal behavior context of the terminal are obtained. The abnormal behavior context includes abnormal operation type, abnormal access target, and historical behavior pattern. According to the risk response dimension indicators in the quantifiable control indicator list generated in step S16, the handling strategy corresponding to the current risk level is matched.
[0062] S42. Immediate Blocking and Isolation: Generate blocking and isolation instructions based on the handling strategies defined in the risk response dimension indicators; through the ACL instruction conversion and distribution in step S3, convert the blocking and isolation instructions into ACL configuration instructions executable by the target switch, and distribute them to the switch port accessed by the terminal to block all access from the network layer.
[0063] S43. Precise location of abnormal terminals: Query the device information (MAC address, device serial number) of the terminal in the known asset database based on the terminal identifier; locate the physical location of the abnormal terminal based on the terminal identifier and the current access port number, combined with the network topology diagram constructed in step S11, including the access switch identifier, switch IP address, port number, rack number, and site name; associate the location results with the abnormal event record.
[0064] S44. Joint Response and Work Order Push: Based on the joint response strategy defined in the risk response dimension indicators of the quantifiable control indicator list generated in step S16, execute the joint response with external security devices: Firewall linkage: Push blacklist rules to the firewall system to add the terminal's IP address or MAC address to the blacklist; Linked antivirus system: Sends virus scanning commands to the antivirus system, triggering a remote virus scan of the terminal; Link up with the situational awareness platform: Push risk intelligence to the situational awareness platform and update the threat intelligence database.
[0065] Push the handling work order to the operation and maintenance platform. The work order content includes the abnormal terminal identifier, physical location, description of abnormal behavior, risk level, executed handling measures and suggested handling solutions.
[0066] S45. Anomaly Removal Confirmation and Policy Revocation: Continuously monitor the status of abnormal terminals, and determine whether the anomaly has been removed by using a multi-source anomaly removal confirmation method (when any confirmation method reports that the anomaly has been removed, it is determined that the anomaly removal is complete). After confirming that the anomaly has been removed, generate a policy revocation command; through the ACL command conversion and distribution mechanism in step S3, distribute the revocation command to the corresponding switch port, delete or disable the previously distributed blocking ACL rules, and restore the normal access permissions of the terminal.
[0067] The methods for confirming the exclusion of multi-source anomalies include: The maintenance personnel marked the exception as resolved in the work order; The antivirus system reports that the virus has been removed; Continuous network behavior monitoring confirmed that the terminal behavior has returned to normal.
[0068] S46. Handling Records and Audit Archiving: Record and store the complete anomaly handling process in the policy log library, and associate it with the terminal identifier, anomaly behavior context, handling time, handling results at each stage, and recovery time (policy revocation execution time); synchronously update the security status field of the terminal in the known asset library and mark it as "handled - normal"; if the asset library information is found to be inaccurate during the handling process (such as terminal location change), synchronously update the corresponding field in the known asset library.
[0069] This invention constructs a three-level mapping model of "scenario-terminal-port" and a quantifiable list of control indicators, transforming the access processes and security compliance requirements of multiple scenarios in railway communication sections into structured policy rules, laying a precise foundation for dynamic ACL generation. It employs a three-level progressive authentication method (subject identity, device identity, device health) combined with real-time network behavior monitoring, achieving accurate identification and dynamic rating of terminal identity and risk status, thus solving the security blind spots of traditional single-dimensional verification. Based on a combination of a multi-dimensional policy mapping matrix and a Cartesian product, it integrates and maps five-dimensional parameters: terminal identity, status, risk level, time, and location. As a fine-grained ACL policy template, combined with a dual-channel architecture of in-band mirror awareness and out-of-band command issuance, it realizes automatic adaptation, reliable issuance, and effectiveness verification of switch commands, solving the problems of poor compatibility of heterogeneous network devices and cumbersome manual configuration. Furthermore, through a four-stage closed loop for anomaly handling (instant blocking, precise location, coordinated handling, and automatic recovery), it constructs a complete security closed loop from threat discovery to handling and recovery, effectively reducing operation and maintenance costs. Overall, it achieves "zero-modification deployment, full terminal coverage, and intelligent operation and maintenance throughout the entire process" for railway communication network terminal access control, significantly improving network security protection level and operation and maintenance efficiency.
[0070] The above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention in any way. Although the present invention has been disclosed above with reference to preferred embodiments, it is not intended to limit the present invention. Any person skilled in the art can make some modifications or alterations to the above-disclosed technical content to create equivalent embodiments without departing from the scope of the present invention. Any simple modifications, equivalent changes and alterations made to the above embodiments based on the technical essence of the present invention without departing from the scope of the present invention shall still fall within the scope of the present invention.
Claims
1. A method for terminal access control in railway communication networks based on dynamic ACL, characterized in that: Includes the following steps: Network environment perception and demand modeling: Collect information on network equipment and terminals in railway communication sections, extract access processes, control requirements and security compliance requirements for various business scenarios, decompose them into atomic control indicators, and generate a list of control indicators through three-level mapping; Terminal authentication and risk perception: The system verifies the identity and assesses the status of terminals entering the network through a three-level progressive verification process, comprehensively evaluates the risk level based on real-time network behavior, and outputs handling strategies. Dynamic ACL generation and automatic distribution: Based on the decision instructions and terminal status in the handling policy, an ACL template is generated through multi-dimensional policy mapping, converted into switch instructions and distributed for execution, and the dynamic allocation and confirmation of permissions are completed. Anomaly tracing and security handling: After detecting an abnormal terminal, it is immediately blocked and isolated, its physical location is located, a work order is pushed and external devices are coordinated to handle the situation, and permissions are automatically restored after the anomaly is resolved, completing the security loop and audit archiving.
2. The railway communication network terminal access control method based on dynamic ACL according to claim 1, characterized in that: The network environment awareness and demand modeling includes the following steps: Network device information collection: Scan the entire network devices of the railway communication section using Simple Network Management Protocol to obtain basic information about the switches; at the same time, use Network Topology Discovery Protocol to obtain the connection relationships between network devices and construct a network topology diagram. Terminal access information collection: Network traffic is obtained through switch port mirroring technology, and combined with Address Resolution Protocol (ARP) monitoring and Dynamic Host Configuration Protocol (DHCP) message analysis, to identify terminal device information accessing the network, including existing access basic information and existing device fingerprint information; Business scenario identification and requirement extraction: Based on the collected network device information and terminal access information, identify the types of business scenarios within the communication segment; for each business scenario, extract the corresponding access process, control requirements and security compliance requirements; Atomized decomposition of requirements indicators: The extracted control requirements and security compliance requirements are decomposed into atomic control indicators. Each atomic control indicator has quantifiable parameter thresholds and executable judgment logic. Demand mapping model construction: Dispersed, multi-source demand data is structured and organized through a three-layer mapping relationship to generate a scenario-terminal-port demand mapping model.
3. The railway communication network terminal access control method based on dynamic ACL according to claim 2, characterized in that: The basic information of the switch includes the device brand and model, device IP address, device operating status, port list and port configuration parameters; The existing access basic information includes MAC address, IP address, access switch identifier, and access port number; the existing device fingerprint information includes operating system type, operating system version, hardware signature, and device serial number; The business scenarios include core data center scenarios, unattended station scenarios, and outdoor front-end equipment scenarios. The access process includes a terminal registration process, an authentication process, and a permission application process. The control requirements include authentication strength, access permissions, and audit policies. The security compliance requirements include requirements for terminal access control, boundary protection, and security auditing. The atomized control indicators include time-dimensional indicators, location-dimensional indicators, operation-type-dimensional indicators, terminal-type-dimensional indicators, and risk response-dimensional indicators; The demand mapping model includes: First-level mapping: Establish a mapping relationship between business scenarios and access terminal types, and determine the set of terminal types that are allowed to access in each scenario; Second-level mapping: Establish a mapping relationship between the access terminal type and the switch port to determine the range of switch ports that each type of terminal can access; The third level of mapping establishes a mapping relationship between atomic control indicators and port-level policies, determining the control policy parameters that should be executed for each port.
4. The railway communication network terminal access control method based on dynamic ACL according to claim 1, characterized in that: The terminal authentication and risk awareness include the following steps: Terminal access triggering and basic information extraction: When a terminal device accesses the network, the network traffic initiated by the terminal is captured through switch port mirroring technology. Combined with Address Resolution Protocol (ARP) monitoring and Dynamic Host Configuration Protocol (DHCP) message analysis, the real-time access basic information of the terminal is extracted. At the same time, probe messages are sent to the terminal through active probing technology to obtain the terminal's real-time device fingerprint information. Entity authentication: Based on the business requirements of the access scenario, select the corresponding authentication mode for entity authentication; extract the authentication information and compare it with the pre-set legitimate entity database in the system to determine the legitimacy of the access entity's identity; if the entity authentication fails, directly trigger the blocking and isolation to terminate the subsequent verification process; if the verification passes, record the entity's identity identifier and proceed to the next level of verification. Device authentication: The real-time device fingerprint information is compared with the known asset database to determine whether the access device belongs to a legitimate potential member. If the device authentication fails, it is judged as an asset impersonation risk, triggering a medium risk warning and implementing differentiated handling strategies. If the authentication passes, the device identifier is recorded and the process proceeds to the next level of authentication. Device health verification: Obtain the health check strategy corresponding to the terminal based on the device identifier, check the terminal's security indicators, calculate the terminal's health score using a weighted scoring method based on the check results of each security indicator, compare the health score with a preset threshold, and output the health status judgment result. Verification Result Synthesis and Risk Level Assessment: The results of subject authentication, device authentication, and device health verification are combined to form a three-level verification status vector, denoted as (V1, V2, V3), where V1, V2, and V3 represent the results of subject authentication, device authentication, and device health verification, respectively. Based on real-time network behavior and preset risk assessment rules, the risk level of the terminal is comprehensively assessed, and finally, a handling strategy is output based on the risk level and trust status.
5. The railway communication network terminal access control method based on dynamic ACL according to claim 4, characterized in that: The real-time access basic information includes the terminal's MAC address, IP address, access switch identifier, and access port number; The real-time device fingerprint information includes operating system type, operating system version, hardware signature, device serial number, and list of open ports; The authentication modes include IP+MAC binding authentication, account password authentication, and facial recognition authentication; The known asset database is a pre-established list of legitimate terminal devices, including multi-dimensional fingerprint information of all registered terminals, which serves as a comparison benchmark for device authentication. The security indicators include patch installation status, software compliance, service status, antivirus software running status, and firewall enabling status. The output health status determination result includes: If the health score is higher than the first threshold, the person is considered healthy. If the health score is between the first and second thresholds, it is judged as sub-healthy, triggering a low-risk warning. If the health score is below the second threshold, it is considered high-risk, triggering a medium-risk warning. The preset rules for risk assessment include: If V1=passed, V2=passed, and V3=healthy, and there are no abnormalities in network behavior, then it is assessed as low risk and the terminal is marked as trusted. If V1 = Pass, V2 = Pass, and V3 = Healthy, but there are abnormal network behaviors, it is assessed as medium risk; If V1 = Pass, V2 = Pass, and V3 = Sub-healthy, then it is assessed as low risk and the terminal is marked as sub-healthy. If V1 = Pass, V2 = Pass, and V3 = High Risk, then the risk level is assessed as medium risk, and the terminal is marked as high risk. If V1 = Pass and V2 = Fail, the risk level is assessed as medium and the terminal is marked as counterfeit risk. If V1 fails, it is assessed as a serious risk and the terminal is marked as an illegal entity. The handling strategy includes: Low-risk and trusted status: The decision instruction is for normal access. The decision instruction, terminal identifier, and trusted status are output to the next step. Low-risk and sub-healthy state: The decision instruction is to downgrade the access, output the decision instruction, terminal identifier and trust status to the next step, and push a patch repair prompt; Medium risk: The decision instruction is to restrict access. The decision instruction, terminal identifier, and trusted status are output to the next step, and an alarm notification is pushed. High risk / Severe risk: The decision instruction is to block and isolate, and output the decision instruction, terminal identifier and trusted status to the next step.
6. The railway communication network terminal access control method based on dynamic ACL according to claim 1, characterized in that: The dynamic ACL generation and automatic distribution include the following steps: Policy input parameter acquisition: Receive terminal identifier, trust status, risk level and decision instructions; query terminal type in known asset database based on terminal identifier; match corresponding control record from control indicator list based on terminal identifier and current access port number; obtain time constraint, location constraint and permission scope parameters of terminal in current scenario. Based on the decision command mapping policy parameters: if the decision command is for normal access, the authorization scope is configured according to the permission scope parameters, with no rate limit; if it is for downgraded access, the authorization scope is configured according to the isolated network segment, with a preset rate limit; if it is for restricted access, the authorization scope is configured according to the isolated network segment, with a strict rate limit; if it is for blocking and isolation, the authorization scope is empty, and all access is blocked. Multi-dimensional ACL policy mapping matrix construction: Based on the obtained terminal type, trust status, risk level, time constraint and location constraint, a mapping matrix is constructed, and the values of each dimension are mapped to the corresponding policy parameters. The policy parameters include authorization scope, access rate limit, audit requirements and authentication strength. Dynamic ACL policy template generation: The multi-dimensional ACL policy mapping matrix is combined by Cartesian product, and each combination corresponds to a preset ACL policy template; the policy templates are sorted by priority, which is determined by the risk level, and under the same risk level, it is determined by the terminal status; higher priority templates override conflicting rules of lower priority templates; ACL command conversion and adaptation: Obtain the brand, model and operating system version of the target switch by collecting basic switch information; match the corresponding command format template from the built-in command template library, fill the authorization scope, access rate limit, audit requirements and authentication strength parameters in the policy template into the command format template, and generate ACL configuration commands that can be executed by the target switch; Automatic ACL command delivery: The command delivery is executed using a dual-channel architecture of in-band mirroring awareness and out-of-band command delivery. For the in-band channel, network traffic information is continuously acquired through switch port mirroring to verify the actual effectiveness of the command after delivery. For the out-of-band channel, the generated ACL configuration command is delivered to the corresponding switch port through the multi-protocol management of the virtual LAN. Policy activation confirmation and status synchronization: Verify that the ACL command has taken effect on the target switch port, read the ACL configuration status of the switch port via SNMP protocol to confirm that the rules have been correctly applied; store the generated dynamic ACL policy record in the policy log library, and associate it with terminal identifier, timestamp, policy content, and distribution result; synchronously update the current effective policy field of the terminal in the known asset library for reference when adjusting or revoking policies in the future.
7. The railway communication network terminal access control method based on dynamic ACL according to claim 6, characterized in that: The terminal types include server terminals, industrial control terminals, monitoring terminals, and office terminals; the policy template includes fields for authorization scope, access rate limit, audit requirements, and authentication strength.
8. The railway communication network terminal access control method based on dynamic ACL according to claim 1, characterized in that: The anomaly tracing and security handling include the following steps: Abnormal Terminal Detection and Triggering: Based on a continuous risk awareness mechanism, the network behavior of connected terminals is monitored in real time. When abnormal behavior is detected, the abnormal handling process is triggered. The terminal identifier, current risk level, and abnormal behavior context of the terminal are obtained. According to the risk response dimension indicators in the control indicator list, the handling strategy corresponding to the current risk level is matched. Real-time blocking and isolation: Generate blocking and isolation instructions based on the handling strategy; through ACL instruction conversion and distribution, convert the blocking and isolation instructions into ACL configuration instructions executable by the target switch, and distribute them to the switch port to which the terminal is connected, blocking all access of the abnormal terminal from the network layer; Precise location of abnormal terminals: Based on the terminal identifier, query the terminal's device information in the known asset database; based on the terminal identifier and the current access port number, and combined with the network topology diagram, locate the physical location of the abnormal terminal, including the access switch identifier, switch IP address, port number, rack number, and site name, and associate the location results with the abnormal event record; Joint response and work order push: Based on the joint response strategy defined in the risk response dimension indicators in the control indicator list, execute the joint response of external security devices and push the response work order to the operation and maintenance platform. The work order content includes abnormal terminal identification, physical location, abnormal behavior description, risk level, executed response measures and suggested handling solutions. Anomaly removal confirmation and policy revocation: Continuously monitor the status of abnormal terminals, determine whether the anomaly has been removed through multi-source anomaly removal confirmation, and generate a policy revocation command after confirming that the anomaly has been removed; through the ACL command conversion and distribution mechanism, the revocation command is distributed to the corresponding switch port to delete or disable the previously distributed blocking ACL rules and restore the normal access permissions of the terminal. Handling Records and Audit Archiving: Record and store the complete anomaly handling process in the policy log library, and associate it with terminal identifier, anomaly behavior context, handling time, handling results at each stage and recovery time; synchronously update the terminal's security status field in the known asset library.
9. The railway communication network terminal access control method based on dynamic ACL according to claim 8, characterized in that: The external security device linkage includes: Firewall linkage: Push blacklist rules to the firewall system and add the terminal's IP address or MAC address to the blacklist; Linked antivirus system: Sends virus scanning commands to the antivirus system, triggering a remote virus scan of the terminal; Link up with the situational awareness platform: Push risk intelligence to the situational awareness platform and update the threat intelligence database.
10. A railway communication network terminal access control method based on dynamic ACL according to claim 9, characterized in that: The multi-source anomaly exclusion confirmation method includes: The maintenance personnel marked the exception as resolved in the work order; The antivirus system reports that the virus has been removed; Continuous network behavior monitoring confirmed that the terminal behavior has returned to normal.