Rail transit network security protection method, device and equipment and storage medium
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-05-25
- Publication Date
- 2026-08-11
AI Technical Summary
[0003]然而,上述方案在复杂工况下,因环境因素引发的设备噪声波动极易导致模型产生大量误报,且集中式架构在通信异常场景下会丧失本地自主防护能力,造成网络安全防护的连续性中断
Smart Images

Figure CN122554850A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of rail transit network security protection technology, and in particular to a rail transit network security protection method, device, equipment and storage medium. Background Technology
[0002] Currently, rail transit network security protection technologies are mostly designed for conventional plain environments. Their hardware architecture typically consists of industrial-grade firewalls, intrusion detection systems, and onboard security gateways deployed in the train backbone network and vehicle control network, forming a multi-layered boundary protection system. At the software level, these solutions primarily rely on static rule bases and anomaly detection models based on fixed thresholds. They identify and block attacks by performing pattern matching on network traffic characteristics and parsing the compliance of communication protocols. Some improved solutions further introduce status monitoring mechanisms, collecting feedback status from train speed, traction, and braking systems to construct simplified physical association rules to verify the legitimacy of control commands. At the system architecture level, existing solutions mostly adopt a centralized security management unit, aggregating all security monitoring data onto a single processor for unified decision-making.
[0003] However, under complex operating conditions, the above-mentioned solutions are prone to generating a large number of false alarms due to equipment noise fluctuations caused by environmental factors. Furthermore, the centralized architecture will lose its local autonomous protection capability in communication anomaly scenarios, causing a continuous interruption of network security protection. Summary of the Invention
[0004] To address the aforementioned issues, this application provides a method, apparatus, device, and storage medium for cybersecurity protection of rail transit networks, including the following: Firstly, this application provides a method for protecting the network security of rail transit systems, the method comprising: Acquire environmental parameters, electronic map data, and network monitoring data of the train's surroundings; An environmental adaptive baseline is generated based on the environmental parameters and the electronic map data. The environmental adaptive baseline is used to dynamically adjust the judgment boundary of network security detection. A multidimensional feature vector is constructed based on the environmental parameters and the network monitoring data; Multidimensional anomaly detection is performed on the multidimensional feature vector based on the environmental adaptive baseline. In response to anomaly detection results, a tiered response strategy is implemented, and a geographically based vehicle-to-ground-vehicle coordinated defense mechanism is triggered when an attack event is detected.
[0005] Optionally, obtaining environmental parameters and electronic map data of the train's location includes: Acquire at least one environmental parameter, including altitude, atmospheric pressure, ambient temperature, electromagnetic interference intensity, real-time location information of the train, and operating status; Acquire at least one type of electronic map data, including section identification and route feature information.
[0006] Optionally, generating an environmental adaptive baseline based on the environmental parameters and the electronic map data includes: The sensitivity threshold for network traffic detection is dynamically adjusted based on the intensity of electromagnetic interference. The normal fluctuation range of the sensor signal is corrected based on altitude and ambient temperature; A switching determination baseline for the location information source is generated based on the satellite signal strength, the segment identifier, and the real-time location.
[0007] Optionally, constructing a multidimensional feature vector based on the environmental parameters and the network monitoring data includes: The environmental parameters, the network monitoring data, and the spatiotemporal features extracted from the electronic map data are spatiotemporally aligned. Using timestamps and geographic locations as unified indexes, a multi-dimensional feature vector containing environmental features, spatiotemporal features, network features, control features, and feedback features is generated; The environmental characteristics include altitude, temperature, humidity, and electromagnetic interference intensity; The spatiotemporal features include the train's real-time location, section identifier, timestamp, and communication link status; The network characteristics include source IP address, destination IP address, protocol type, instruction content, traffic rate, and message interval. The control features include traction power commands, braking commands, and bogie control commands; The feedback features include traction current, brake cylinder pressure, speed, and acceleration.
[0008] Optionally, the multidimensional anomaly detection based on the environmental adaptive baseline on the multidimensional feature vector includes: The environmental adaptive baseline is used as the dynamic decision boundary, and the spatiotemporal consistency verification, environment-physical correlation verification, and electromagnetic interference and attack feature separation are performed sequentially on the multidimensional feature vector.
[0009] Optionally, the step of calling the environmental adaptive baseline as a dynamic determination boundary and sequentially performing spatiotemporal consistency verification, environment-physical correlation verification, and electromagnetic interference and attack feature separation on the multidimensional feature vector includes: Perform the spatiotemporal consistency check. If the check fails, a level 3 alarm is triggered directly. If the check passes, continue to perform the environment-physical association check. Perform the environment-physical association verification. If the verification fails, trigger a level 3 alarm. If the verification passes, continue to perform the separation of electromagnetic interference and attack characteristics. The process involves separating electromagnetic interference from attack characteristics. If the interference is determined to be environmental interference, a Level 1 alarm is triggered. If the interference is determined to be malicious, a Level 2 alarm is triggered.
[0010] Optionally, the implementation of the hierarchical response strategy includes: When the Level 1 alarm is triggered, only abnormal event information is recorded; When the secondary alarm is triggered, the communication permissions of the affected network ports are restricted, and a vehicle-to-ground-to-vehicle coordinated defense mechanism based on geographical location is triggered. If the communication link is interrupted, the attack characteristics and geographical segment number are cached locally and synchronized to the ground security management center after the communication link is restored. The ground security management center generates standardized early warning information and broadcasts it to subsequent trains, so that the subsequent trains can activate the enhanced monitoring strategy before entering the corresponding segment. When the Level 3 alarm is triggered, the connection between the attacked subsystem and the train network is cut off, triggering a degraded train safety operation. When the communication link is interrupted, the system switches to a local autonomous protection mode, forcibly triggering a vehicle-to-ground-vehicle coordinated defense mechanism based on geographical location. The attack characteristics and geographical segment number are cached locally and synchronized to the ground safety management center after the communication link is restored. The ground safety management center generates standardized early warning information and broadcasts it to subsequent trains, enabling the subsequent trains to activate enhanced monitoring strategies before entering the corresponding segment.
[0011] Optionally, the execution of the spatiotemporal consistency check, and the direct triggering of a level three alarm if the check fails, includes: When the train is running in a tunnel and the communication link is interrupted, if the spatiotemporal consistency check detects a remote command from the ground dispatch center, and the environment-physical correlation check detects that the power value of the remote command exceeds a preset percentage of the upper limit of the power model based on the current altitude, a level three alarm is triggered. At the same time, the traction control network interface is isolated, causing the traction controller to automatically switch to the local safe power curve and limit the speed to a preset safe value. A mandatory alarm prompt is issued to the driver, allowing the train to continue running until the next station for maintenance.
[0012] Optionally, the triggering of geographic coordination defense includes: When the first train detects a traction command tampering attack in a tunnel on the plateau line, an attack report containing attack characteristics and geographical segment number is generated and cached locally. After the first train exits the tunnel, the attack report will be uploaded to the ground security management center. The ground safety management center broadcast a warning message to the second train behind it. Before entering the corresponding tunnel section, the second train automatically loads an enhanced monitoring strategy based on the warning information, and directly intercepts the train when it receives a suspicious instruction from the same source again.
[0013] Optionally, the execution of the environment-physical association verification, and the triggering of a level three alarm if the verification fails, includes: Verify whether the output power of the traction command matches the atmospheric pressure and rated power of the traction motor corresponding to the current altitude, and verify whether the execution intensity of the braking command is suitable for the current track gradient, train load and ambient temperature. If the verification fails, a level three alarm is triggered.
[0014] Optionally, performing the separation of electromagnetic interference and attack characteristics includes: Compare with the normal noise baseline of the equipment under the current electromagnetic interference intensity; If the abnormal characteristics are synchronized with the electromagnetic interference characteristics, it is determined to be environmental interference and a level one alarm is triggered. If the abnormal characteristics are not synchronized with the electromagnetic interference characteristics, it is determined to be a malicious network attack and a level 2 alarm is triggered.
[0015] Secondly, this application provides a rail transit network security protection device, which includes: The acquisition unit is used to acquire environmental parameters, electronic map data, and network monitoring data of the train's environment. The baseline generation unit is used to generate an environment-adaptive baseline based on the environmental parameters and the electronic map data. The environment-adaptive baseline is used to dynamically adjust the judgment boundary of network security detection. A vector construction unit is used to construct a multidimensional feature vector based on the environmental parameters and the network monitoring data; An anomaly detection unit is used to perform multidimensional anomaly detection on the multidimensional feature vector based on the environmental adaptive baseline. The response execution unit is used to respond to anomaly detection results, execute hierarchical response strategies, and trigger a geographically based vehicle-to-ground-vehicle coordinated defense mechanism when an attack event is detected.
[0016] Optionally, the acquisition unit is specifically used to acquire at least one environmental parameter, including altitude, atmospheric pressure, ambient temperature, electromagnetic interference intensity, real-time location information of the train, and operating status. Acquire at least one type of electronic map data, including section identification and route feature information.
[0017] Optionally, the baseline generation unit is specifically used to dynamically adjust the sensitivity threshold of network traffic detection based on the intensity of electromagnetic interference. The normal fluctuation range of the sensor signal is corrected based on altitude and ambient temperature; A switching determination baseline for the location information source is generated based on the satellite signal strength, the segment identifier, and the real-time location.
[0018] Optionally, the vector construction unit is specifically used to perform spatiotemporal alignment of the environmental parameters, the network monitoring data, and the spatiotemporal features extracted from the electronic map data; Using timestamps and geographic locations as unified indexes, a multi-dimensional feature vector containing environmental features, spatiotemporal features, network features, control features, and feedback features is generated; The environmental characteristics include altitude, temperature, humidity, and electromagnetic interference intensity; The spatiotemporal features include the train's real-time location, section identifier, timestamp, and communication link status; The network characteristics include source IP address, destination IP address, protocol type, instruction content, traffic rate, and message interval. The control features include traction power commands, braking commands, and bogie control commands; The feedback features include traction current, brake cylinder pressure, speed, and acceleration.
[0019] Optionally, the anomaly detection unit is specifically used to call the environmental adaptive baseline as a dynamic judgment boundary, and sequentially perform spatiotemporal consistency verification, environmental-physical correlation verification, and electromagnetic interference and attack feature separation on the multidimensional feature vector.
[0020] Optionally, the step of calling the environmental adaptive baseline as a dynamic determination boundary and sequentially performing spatiotemporal consistency verification, environment-physical correlation verification, and electromagnetic interference and attack feature separation on the multidimensional feature vector includes: Perform the spatiotemporal consistency check. If the check fails, a level 3 alarm is triggered directly. If the check passes, continue to perform the environment-physical association check. Perform the environment-physical association verification. If the verification fails, trigger a level 3 alarm. If the verification passes, continue to perform the separation of electromagnetic interference and attack characteristics. The process involves separating electromagnetic interference from attack characteristics. If the interference is determined to be environmental interference, a Level 1 alarm is triggered. If the interference is determined to be malicious, a Level 2 alarm is triggered.
[0021] Optionally, the response execution unit is specifically used to record only abnormal event information when the first-level alarm is triggered; When the secondary alarm is triggered, the communication permissions of the affected network ports are restricted, and a vehicle-to-ground-to-vehicle coordinated defense mechanism based on geographical location is triggered. If the communication link is interrupted, the attack characteristics and geographical segment number are cached locally and synchronized to the ground security management center after the communication link is restored. The ground security management center generates standardized early warning information and broadcasts it to subsequent trains, so that the subsequent trains can activate the enhanced monitoring strategy before entering the corresponding segment. When the Level 3 alarm is triggered, the connection between the attacked subsystem and the train network is cut off, triggering a degraded train safety operation. When the communication link is interrupted, the system switches to a local autonomous protection mode, forcibly triggering a geographically based vehicle-to-ground-vehicle coordinated defense mechanism. The attack characteristics and geographical segment numbers are cached locally and synchronized to the ground safety management center after the communication link is restored. The ground safety management center generates standardized early warning information and broadcasts it to subsequent trains, enabling the subsequent trains to activate enhanced monitoring strategies before entering the corresponding segment.
[0022] Optionally, the execution of the spatiotemporal consistency check, and the direct triggering of a level three alarm if the check fails, includes: When the train is running in a tunnel and the communication link is interrupted, if the spatiotemporal consistency check detects a remote command from the ground dispatch center, and the environment-physical correlation check detects that the power value of the remote command exceeds a preset percentage of the upper limit of the power model based on the current altitude, a level three alarm is triggered. At the same time, the traction control network interface is isolated, causing the traction controller to automatically switch to the local safe power curve and limit the speed to a preset safe value. A mandatory alarm prompt is issued to the driver, allowing the train to continue running until the next station for maintenance.
[0023] Optionally, the triggering of geographic coordination defense includes: When the first train detects a traction command tampering attack in a tunnel on the plateau line, an attack report containing attack characteristics and geographical segment number is generated and cached locally. After the first train exits the tunnel, the attack report will be uploaded to the ground security management center. The ground safety management center broadcast a warning message to the second train behind it. Before entering the corresponding tunnel section, the second train automatically loads an enhanced monitoring strategy based on the warning information, and directly intercepts the train when it receives a suspicious instruction from the same source again.
[0024] Optionally, the execution of the environment-physical association verification, and the triggering of a level three alarm if the verification fails, includes: Verify whether the output power of the traction command matches the atmospheric pressure and rated power of the traction motor corresponding to the current altitude, and verify whether the execution intensity of the braking command is suitable for the current track gradient, train load and ambient temperature. If the verification fails, a level three alarm is triggered.
[0025] Optionally, performing the separation of electromagnetic interference and attack characteristics includes: Compare with the normal noise baseline of the equipment under the current electromagnetic interference intensity; If the abnormal characteristics are synchronized with the electromagnetic interference characteristics, it is determined to be environmental interference and a level one alarm is triggered. If the abnormal characteristics are not synchronized with the electromagnetic interference characteristics, it is determined to be a malicious network attack and a level 2 alarm is triggered.
[0026] Thirdly, this application provides an apparatus comprising a memory and a processor, the memory for storing instructions or code, and the processor for executing the instructions or code to cause the apparatus to perform the rail transit network security protection method described in any of the implementations of the first aspect.
[0027] Fourthly, this application provides a computer-readable storage medium storing code, wherein when the code is executed, a device running the code implements the rail transit network security protection method described in any of the implementations of the first aspect.
[0028] This application provides a method for protecting the network security of rail transit. When executing the method, firstly, environmental parameters, electronic map data, and network monitoring data of the train's environment are acquired. Then, an environmental adaptive baseline is generated based on the environmental parameters and the electronic map data. This environmental adaptive baseline is used to dynamically adjust the judgment boundary of network security detection. Next, a multi-dimensional feature vector is constructed based on the environmental parameters and the network monitoring data. Finally, multi-dimensional anomaly detection is performed on the multi-dimensional feature vector based on the environmental adaptive baseline. In response to the anomaly detection results, a hierarchical response strategy is executed.
[0029] In this way, by constructing an environment-adaptive baseline using environmental parameters as dynamic input variables, the judgment boundary of network security detection can be adjusted in real time according to environmental changes, solving the problem of high false alarm rate of fixed threshold models in complex operating conditions in existing technologies. By constructing multi-dimensional feature vectors and performing multi-dimensional anomaly detection based on the environment-adaptive baseline, anomaly judgment can be jointly analyzed in conjunction with the environmental context, achieving the effect of accurately distinguishing between environmental interference and malicious attacks. By implementing a hierarchical response strategy and switching to a local autonomous protection mode when communication is abnormal, the system can maintain protection continuity even under harsh operating conditions. Thus, deep adaptation of rail transit network security protection to complex environments has been achieved, improving the accuracy of attack identification and the reliability of protection. Attached Figure Description
[0030] To more clearly illustrate the technical solutions in this embodiment or the prior art, the drawings used in the description of the embodiment or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0031] Figure 1 A flowchart illustrating a method for protecting the network security of rail transit, as provided in this application embodiment; Figure 2 This is a schematic diagram of the multi-source environmental parameter acquisition interface architecture provided in the embodiments of this application; Figure 3 This is a block diagram of the anomaly detection and graded response logic provided in the embodiments of this application; Figure 4 A geolocation-coordinated defense timing diagram provided for embodiments of this application; Figure 5 This is a schematic diagram of the structure of a rail transit network security protection device provided in an embodiment of this application. Detailed Implementation
[0032] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.
[0033] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of related data must comply with the relevant laws, regulations and standards of the relevant countries and regions.
[0034] Figure 1 A flowchart illustrating a method for protecting rail transit network security as provided in this application embodiment. (In conjunction with...) Figure 1 As shown, the rail transit network security protection method provided in this application embodiment may include: Acquiring environmental parameters and electronic map data of the train's environment includes: acquiring at least one environmental parameter including altitude, atmospheric pressure, ambient temperature, electromagnetic interference intensity, real-time location information of the train, and operating status; and acquiring at least one electronic map data including section identification and line feature information.
[0035] In this embodiment of the application, environmental parameters are collected through a multi-source environmental parameter acquisition interface, such as... Figure 2 As shown, Figure 2 This diagram illustrates the multi-source environmental parameter acquisition interface architecture provided in this application embodiment. The multi-source environmental parameter acquisition interface layer serves as the raw data input end. By integrating multiple types of dedicated sensors and data interfaces, it enables parallel real-time acquisition of environmental parameters, train status parameters, and network status parameters across the entire operation scenario of plateau rail transit. All acquired data is synchronously output with a time granularity of 100 milliseconds to ensure spatiotemporal consistency of the data.
[0036] The specific components and functions of the data acquisition interface are as follows: A barometric pressure sensor collects atmospheric pressure data in real time at the train's operating location and calculates the current altitude based on a standard atmospheric physics model, with an accuracy of ±5 meters. This data is used to characterize the train's altitude gradient and is subsequently used to correct the electrical characteristic baseline of electronic equipment and the power output baseline of the traction and braking system in high-altitude environments. A temperature and humidity sensor monitors the operating environment temperature and relative humidity of the onboard network equipment in real time, covering a range from -40°C to 85°C, adapting to extreme low-temperature conditions at high altitudes, and a relative humidity range of 0% to 100%. This data is used to quantify the impact of ambient temperature and humidity on the noise level and signal transmission attenuation of electronic equipment, and is used to dynamically correct the monitoring baseline of the sensor data. A spectrum sensor scans the electromagnetic interference intensity of the train's operating frequency bands in real time. The scanned operating frequency bands include industrial communication bands such as MVB and TRDP, satellite communication bands, and terrestrial mobile communication bands, with a frequency coverage range of 10 kHz to 6 GHz and a dynamic range of -100 dB / mW to 0 dB / mW. This sensor simultaneously collects key indicators of the communication link, such as signal-to-noise ratio, bit error rate, and packet loss rate, to assess the impact of the current electromagnetic environment on network communication quality. This data is then used to adjust network traffic detection thresholds and communication link monitoring baselines. Furthermore, the sensor acquires train location and operating status by fusing multi-source positioning data from satellite positioning, inertial navigation systems, and track odometers. This allows for the acquisition of real-time train location, speed, acceleration, track gradient, and curve radius. Satellite positioning data includes, for example, the Global Navigation Satellite System (GNSS). In satellite signal blind spots such as tunnels, it automatically switches to a combined positioning mode using inertial navigation systems and odometers, maintaining positioning accuracy within ±10 meters. This positioning data is then used to match pre-stored electronic maps of plateau routes, enabling baseline segmentation adaptation based on geographical features and subsequent spatiotemporal consistency verification.
[0037] Network security monitoring data serves as input for subsequent multi-dimensional anomaly detection, combining with the aforementioned environmentally adaptive dynamic baseline for further detection and analysis. Specifically, network traffic data refers to communication messages between the train backbone network and the vehicle control network, such as communication messages conforming to protocols like MVB, CANopen, and TRDP, containing information such as source address, destination address, protocol type, instruction content, and timestamp. Control commands originate from the driver's console, the automatic train control system, or the ground dispatch center, such as traction commands, braking commands, door control commands, and levitation control commands. Sensor feedback data refers to actual execution feedback values such as traction current, brake cylinder pressure, speed, and acceleration.
[0038] S102. An environmental adaptive baseline is generated based on the environmental parameters and the electronic map data. The environmental adaptive baseline is used to dynamically adjust the judgment boundary of network security detection.
[0039] Specifically, generating an environment-adaptive baseline includes the following aspects: dynamically adjusting the sensitivity threshold of network traffic detection based on the intensity of electromagnetic interference; correcting the normal fluctuation range of sensor signals based on altitude and ambient temperature; and generating a switching determination baseline for the location information source based on satellite signal strength, segment identification, and real-time location.
[0040] Taking the switching of positioning information sources as an example, when satellite signals are limited, the system automatically switches positioning strategies based on the characteristics of different sections. In open plateau areas with normal satellite signals, the system primarily uses the Global Navigation Satellite System (GNSS), supplemented by wheel speed sensors and an inertial navigation system for fusion positioning, ensuring continuous and high-precision position output. In tunnel complexes or mountainous canyon areas where satellite signals are completely lost, a combination of wheel speed sensors, an inertial navigation system, and electronic map matching is used. The wheel speed sensors provide distance traveled, the inertial navigation system provides attitude and acceleration, and the electronic map is used to correct accumulated errors, achieving reliable positioning under satellite-free conditions. In sections with weak satellite signals and interrupted wireless communication, such as deep within long tunnels, dead reckoning is further performed using onboard wheel speed sensors and accelerometers, combined with pre-set electronic map landmark information, such as transponders and track circuit nodes, for position correction. In sections with strong electromagnetic interference, which may affect the GNSS and sensors, in addition to the above combinations, electronic map matching and absolute position verification based on track circuits are prioritized to reduce reliance on susceptible sensors.
[0041] The generated environmental adaptive baseline does not exist independently, but serves as a dynamic reference threshold and normalization benchmark in subsequent multidimensional anomaly detection, directly participating in three verification judgments: spatiotemporal consistency verification, environmental-physical correlation verification, and separation of electromagnetic interference and attack features.
[0042] Traditional fixed-threshold models generate numerous false alarms in high-altitude environments due to noise fluctuations in electronic devices. In contrast, the adaptive baseline in this solution dynamically adjusts the sensitivity thresholds for each detection dimension based on real-time environmental parameters, providing a dynamic judgment boundary for anomaly detection. Taking network traffic baseline adjustment as an example, in tunnel sections with strong electromagnetic interference, the sensitivity threshold for traffic anomaly detection is lowered from ±2σ to ±3σ. This dynamic threshold is then directly used when calculating network anomaly intensity, thus avoiding misjudging traffic fluctuations caused by interference as attacks. Sensor baseline adjustment dynamically corrects the normal fluctuation range of sensors based on altitude and temperature changes. For example, the steady-state value of a brake cylinder pressure sensor may deviate by 5% at high altitudes and low air pressure. After extracting the sensor feedback value, it is first normalized using the baseline value (i.e., subtracting the baseline mean and dividing by the standard deviation). The normalized residual is then input into the anomaly judgment logic to ensure that physical correlation verification is not affected by environmental drift.
[0043] In terms of spatiotemporal consistency verification, the communication link monitoring baseline in the adaptive baseline outputs the expected communication status of the current segment in real time. For example, tunnel segments are marked as wireless interrupted, and open segments are marked as normal. During spatiotemporal consistency verification, this baseline value is directly used as the judgment criterion: when the baseline's communication status is interrupted and a command from the ground is detected, an anomaly is directly determined; when the baseline's communication status is normal, a more refined reachability comparison is initiated. In this way, the judgment logic can automatically switch according to the train's position, without requiring manual pre-setting.
[0044] For environment-physical correlation verification, real-time filtered values of environmental parameters in the adaptive baseline, including altitude, temperature, and humidity, serve as dynamic inputs to the physical model. For example, the air density value used in the traction power model is directly derived from the results calculated and updated in real time based on altitude and temperature, rather than static preset values. This allows the reasonable range of physical correlation verification to change continuously as the train ascends or descends, ensuring consistency in judgments across different altitude sections.
[0045] Furthermore, the adaptive baseline also serves the electromagnetic interference and attack signature separation process. The real-time output electromagnetic interference intensity is filtered and smoothed, serving as an input sequence for cross-correlation analysis. Simultaneously, the output current environmental electromagnetic interference background noise level is used to normalize the network's abnormal fluctuation amplitude, ensuring that attack signature separation maintains consistent discrimination sensitivity under different interference intensities.
[0046] As can be seen, the environmental adaptive baseline provides dynamic thresholds, context labels, and normalized benchmarks for multidimensional anomaly detection, making all judgment logic no longer static and environment-independent, but adjusting in real time according to the environmental parameters of the plateau section where the train is located, thereby achieving a balance between detection accuracy and environmental adaptability.
[0047] S103. Construct a multidimensional feature vector based on the environmental parameters and the network monitoring data.
[0048] The construction of a multidimensional feature vector based on the environmental parameters and the network monitoring data includes: spatiotemporally aligning the environmental parameters, the network monitoring data, and the spatiotemporal features extracted from the electronic map data; and generating a multidimensional feature vector containing environmental features, spatiotemporal features, network features, control features, and feedback features using timestamps and geographic locations as unified indexes.
[0049] The multidimensional feature vector is a joint feature space constructed by spatiotemporally aligning environmental parameters and network security detection data. Specifically, it includes the following feature parameters: Environmental features, including altitude, temperature, humidity, and electromagnetic interference intensity, with data sourced from the environmental parameter acquisition interface. Spatiotemporal features, including real-time train location, section identification, timestamp, and communication link status. Section identification includes, for example, tunnel sections, bridge sections, and open areas; communication link status includes, for example, satellite signal strength and wireless communication quality, with data sourced from electronic maps, wheel speed sensors, and communication status monitoring. Network features, including source IP address, destination IP address, protocol type, command content, flow rate, and message interval, with data sourced from network traffic mirroring ports. Control features, including traction power commands, braking commands, and bogie control commands, with data sourced from the train control system interface. Feedback features, including traction current, brake cylinder pressure, speed, and acceleration, with data sourced from sensor feedback.
[0050] S104. Perform multidimensional anomaly detection on the multidimensional feature vector based on the environmental adaptive baseline.
[0051] like Figure 3 As shown, Figure 3This is a logical block diagram of anomaly detection and graded response provided in an embodiment of this application. The anomaly detection and graded response process proposed in this application follows a closed-loop logical architecture of two-level progressive verification, feature decoupling and separation, and graded differentiated response. The input for multidimensional anomaly detection is a three-dimensional fusion feature vector that has been preprocessed and spatiotemporally aligned by the aforementioned environmental perception and dynamic baseline generation steps. This feature vector includes environmental feature dimensions, physical state dimensions, and network traffic dimensions. Among them, the environmental feature dimension includes altitude, atmospheric pressure, ambient temperature, electromagnetic interference intensity, communication link signal-to-noise ratio, and packet loss rate; the physical state dimension includes real-time train speed, acceleration, traction power, braking pressure, track gradient, and curve radius; the network traffic dimension includes the average and peak traffic, protocol message length distribution, and connection establishment frequency of the train backbone network and vehicle control network, as well as the message format, transmission timing, command semantics, and permission verification results of industrial communication protocols such as MVB and TRDP. All feature data are updated synchronously with a time granularity of 100 milliseconds to ensure the real-time performance and accuracy of detection decisions. The above inputs, by deeply integrating environmental parameters with network security data and physical operation data, provide complete contextual information for subsequent anomaly detection, laying the foundation for distinguishing between environmental interference and malicious attacks at the data level. The multidimensional anomaly detection based on the environmental adaptive baseline includes: using the environmental adaptive baseline as a dynamic judgment boundary, and sequentially performing spatiotemporal consistency verification, environment-physical correlation verification, and separation of electromagnetic interference and attack features on the multidimensional feature vector.
[0052] Specifically, when performing the spatiotemporal consistency check, if the check fails, a level 3 alarm is triggered directly; if the check passes, the environment-physical association check continues. When performing the environment-physical association check, if the check fails, a level 3 alarm is triggered; if the check passes, the separation of electromagnetic interference and attack characteristics continues. When performing the separation of electromagnetic interference and attack characteristics, if it is determined to be environmental interference, a level 1 alarm is triggered; if it is determined to be a malicious attack, a level 2 alarm is triggered.
[0053] The spatiotemporal consistency verification is performed as follows. The judgment logic involves comparing the real-time train location, communication link status, and network command timestamp and source identifier from the multi-dimensional feature vector. Specifically, the comparison rules are as follows: The communication link status feature is extracted from the feature vector, with values of "tunnel section - wireless interruption" or "coverage section - normal"; the command source identifier feature is extracted, with values of "ground dispatch center," "adjacent train," or "local control station." If the communication link status is "tunnel section - wireless interruption," but the command source identifier is "ground dispatch center," then a spatiotemporal inconsistency is determined, triggering a level three alarm. If the communication link status is "coverage section - normal," then the physical reachability of the command timestamp and train location is further compared. For example, the difference between the train location at the time the command was issued and the current train location; if this difference exceeds a reasonable time window corresponding to the maximum communication coverage area, then the system is deemed suspicious. More specifically, spatiotemporal consistency verification also includes temporal consistency verification, which verifies the matching relationship between the transmission delay of network packets, the instruction execution interval and the train running speed and equipment response time; spatial consistency verification, which verifies the matching relationship between the source address, destination address and communication range of the network connection and the real-time geographical location of the train and the line topology; and spatiotemporal distribution of traffic verification, which verifies whether the network traffic distribution of different carriages and different subsystems matches the train operating section and equipment operating status. If the verification fails, it indicates that there is a significant spatiotemporal inconsistency in network activity, which may indicate serious security threats such as replay attacks, address spoofing, large-scale traffic injection or denial-of-service attacks. The system will directly trigger a level 3 alarm and enter the highest level emergency response process.
[0054] The judgment method for environment-physical correlation verification is as follows. The judgment logic is to compare the output value of the instruction requirement in the multi-dimensional feature vector with the output range of the control model based on the current environmental parameters. Taking the traction control system as an example, the specific comparison rules are as follows: extract the altitude parameter from the feature vector, call the preset altitude-air density mapping function to calculate the air density value at the current altitude; extract the train speed and instruction power value, substitute them into the traction system power model, and the reasonable power upper limit is equal to the function value with altitude, speed, contact network voltage, and motor temperature as variables; at the same time, extract the traction current feedback value and speed feedback value to verify whether the actual execution result is consistent with the instruction requirement. If the instruction power value exceeds the preset threshold of the reasonable power upper limit, for example, 20%, or the conversion relationship between the instruction power value and the traction current feedback value deviates from the physical model by more than ±15%, it is judged as instruction tampering or sensor deception attack, triggering a level 3 alarm. For the braking control system, a similar logic is used: compare the braking instruction value with the braking distance model based on altitude, train load, and current speed. More specifically, the environment-physical correlation verification also includes traction command verification, which verifies whether the output power of the traction command matches the atmospheric pressure and rated power characteristics of the traction motor at the current altitude; braking command verification, which verifies whether the execution intensity of the braking command is compatible with the braking distance requirements under the current track gradient, train load, and ambient temperature; and equipment status verification, which verifies whether the feedback signals of the on-board sensors and actuators are consistent with the normal operating range of the equipment under the current environmental parameters. If the verification fails, it indicates a fundamental contradiction between the network control command and the current environmental and physical state of the train, which is highly likely to be a malicious command tampering attack, and the system will also trigger a level three alarm.
[0055] The method for separating electromagnetic interference (EMI) from attack characteristics is as follows. The judgment logic involves comparing the network anomaly fluctuation characteristics in the multi-dimensional feature vector with the EMI intensity change characteristics in a time-series synchronization manner. The specific comparison rules are: extract the EMI intensity time-series sequence from the feature vector, with a sampling frequency of at least 100 Hz, and calculate its short-time energy change rate; extract the network traffic rate, packet interval time, or error packet ratio from the feature vector and calculate its anomaly fluctuation intensity; use sliding window cross-correlation analysis to calculate the Pearson correlation coefficient between the EMI intensity change curve and the network anomaly intensity change curve. The judgment criteria are: if the correlation coefficient is greater than 0.7, and the anomaly fluctuation does not have a fixed attack pattern in time, such as periodic scanning or specific protocol load, it is determined to be dominated by environmental factors, downgraded to a level one alarm, and only logged; if the correlation coefficient is less than 0.3, and the anomaly fluctuation exhibits fixed attack characteristics, such as repeated attempts at a specific IP address or known vulnerability exploitation load, it is determined to be a network attack, and a level two or three alarm is triggered based on the attack confidence; if the correlation coefficient is between 0.3 and 0.7, deep packet inspection is performed for further identification. More specifically, the electromagnetic interference and attack feature separation process employs a feature decoupling algorithm based on a dynamic baseline, decomposing abnormal features into environment-related and attack-related components: First, the generated real-time dynamic baseline is invoked to obtain the normal noise characteristics of the device and the network traffic fluctuation range corresponding to environmental parameters such as current electromagnetic interference intensity and temperature, i.e., baseline feature matching; then, the Pearson correlation coefficient between abnormal features and changes in environmental parameters is calculated to determine whether the anomaly is caused by environmental factors, i.e., feature correlation analysis; finally, for abnormal features that are not correlated with environmental parameters, attack-specific semantic features and temporal patterns are further extracted, such as instruction field tampering, abnormal privilege escalation, and periodic malicious injection, i.e., attack feature extraction.
[0056] S105. In response to the anomaly detection results, a hierarchical response strategy is executed, and a geographically based vehicle-to-ground-vehicle coordinated defense mechanism is triggered when an attack event is detected.
[0057] The hierarchical response strategy includes: when the Level 1 alarm is triggered, only abnormal event information is recorded; when the Level 2 alarm is triggered, geographically coordinated defense is triggered, and if the communication link is interrupted, the attack characteristics and geographical segment number are cached locally and synchronized to the ground security management center after the communication link is restored, generating early warning information and broadcasting it to subsequent trains, so that the subsequent trains can activate enhanced monitoring strategies before entering the corresponding segment; when the Level 3 alarm is triggered, the connection between the attacked subsystem and the train network is cut off, triggering train safety downgrade operation, and switching to local autonomous protection mode when the communication link is interrupted, while simultaneously triggering geographically coordinated defense, caching the attack characteristics and geographical segment number locally, and synchronizing them to the ground security management center after the communication link is restored, generating early warning information and broadcasting it to subsequent trains, so that the subsequent trains can activate enhanced monitoring strategies before entering the corresponding segment.
[0058] This solution categorizes alerts into three levels based on attack confidence, with each level matched with a corresponding response strategy.
[0059] Level 1 alarms correspond to low-confidence scenarios, where abnormal fluctuations are highly correlated with electromagnetic interference and lack a fixed attack pattern, with an attack confidence level below 30%. In this case, the system determines the anomaly is primarily driven by environmental factors, therefore no network isolation or device blocking is implemented; only the event information is written to the local security log. For example, when a train enters a tunnel complex, an increase in electromagnetic interference intensity causes a brief fluctuation in network traffic. The system, through cross-correlation analysis, determines that the anomaly is synchronized with the electromagnetic interference, triggering a Level 1 alarm. No alarm is displayed in the driver's cab, and normal train operation remains unaffected.
[0060] Level 2 alarms correspond to medium-confidence scenarios, where abnormal fluctuations and electromagnetic interference are asynchronous and exhibit some attack characteristics, with an attack confidence level of 30% to 70%. In this case, the system determines it as a suspected attack and requires local isolation measures: port-level isolation, restricting communication on affected network ports; the driver's cab display prompts the driver to pay attention to the train's status; and the event details are encrypted and stored, to be uploaded to the ground control center once communication is restored. For example, if a train detects repeated port scan attempts from an unfamiliar IP address in an open, high-altitude section but finds no abnormal load, the system sets that port to listening mode, prohibits any subsequent connections from that IP address, and simultaneously sends a notification to the driver, allowing the train to continue operating normally.
[0061] Level 3 alarms correspond to high-confidence scenarios, i.e., when spatiotemporal consistency checks or environment-physical correlation checks fail, or when a clear attack payload is detected with an attack confidence greater than 70%. In this case, the system determines it as a confirmed attack and requires a global emergency response: disconnecting the attacked subsystem from the train network; switching the isolated controller to local safety mode and operating according to a preset safety curve; automatically implementing speed limits or target stopping based on the attack's impact range; and issuing audible and visual alarms in the driver's cab. For example, if a train is running in a tunnel and the spatiotemporal consistency check detects a remote command from the ground while communication is interrupted, and the environment-physical correlation check detects that the command power exceeds the altitude-power model upper limit by 20%, the system immediately isolates the traction control network interface, the traction controller switches to the local safety power curve with a speed limit of 40 km / h, and the train continues running until the next station for maintenance.
[0062] like Figure 4 As shown, Figure 4This application provides a geographic location-coordinated defense timing diagram. This mechanism uses geographic location as the core index and constructs a three-tiered vehicle-to-ground-vehicle coordinated defense system through a sequential process of onboard local detection, data backhaul after communication recovery, directional broadcasting from the ground center, and forward protection by subsequent trains. The core of geographic coordinated defense lies in binding attack events with geographic segment tags and utilizing vehicle-to-ground communication to achieve cross-train propagation. When the source train detects a level 3 alarm, it generates an attack report containing the geographic segment number, environmental tag, attack characteristic payload, and timestamp, which is encrypted and stored in the onboard security unit cache. If the communication link is interrupted, the system waits for the train to exit the tunnel, enter the station, or for the signal to be restored before uploading the attack report to the ground security center using a reliable transmission protocol. After verification and deduplication, the ground center generates a warning message and sends it to approaching trains behind the segment and other trains on the same line. Before subsequent trains enter this section, enhanced monitoring strategies are implemented in advance, marking the section as a high-risk section, conducting in-depth detection or direct filtering of IP addresses and protocol types specified in the warning, adjusting detection sensitivity, and activating local autonomous protection in advance.
[0063] The local autonomous protection mode is designed for communication link interruptions. When the packet loss rate of the communication link continues to exceed 90% for more than 3 seconds, the system automatically decentralizes security decision-making authority from the ground center to the vehicle-mounted security gateway, switching to a fully local autonomous protection mode. The vehicle-mounted system independently performs all anomaly detection, alarm generation, and response handling operations without relying on any remote commands. The vehicle-mounted security gateway caches all security logs and anomaly data in real time, with a cache capacity of no less than 72 hours. When the communication link is restored, the system immediately synchronizes the locally cached security data to the ground center, at which point the geographic coordination defense mechanism comes into play. After receiving the synchronized data, the ground security center verifies the authenticity of the attack event, generates a pre-warning message containing the geographic segment number and attack fingerprint, and broadcasts it to trains approaching behind that segment as well as other trains on the same line, achieving cross-train sharing of attack information and proactive defense.
[0064] The specific implementation methods in the embodiments of this application will be further explained below in conjunction with several typical scenarios.
[0065] For specific application scenarios of spatiotemporal consistency verification and environment-physical correlation verification, when the train is running in a tunnel and the communication link is interrupted, if the spatiotemporal consistency verification detects a remote command from the ground dispatch center, and the environment-physical correlation verification detects that the power value of the remote command exceeds 20% of the upper limit of the power model preset based on the current altitude, the system triggers a level three alarm. Simultaneously, the system immediately isolates the traction control network interface, causing the traction controller to automatically switch to the local safe power curve and limit the speed to 40 kilometers per hour, issuing a mandatory alarm to the driver, allowing the train to continue running to the next station for maintenance.
[0066] For specific application scenarios of geographic coordinated defense, when the first train detects a traction command tampering attack inside a tunnel on a plateau line, it generates an attack report containing attack characteristics and a geographic segment number, and caches it locally. After the first train exits the tunnel, it uploads the attack report to the ground security management center. The ground security management center broadcasts a warning to the second train following behind. Before entering the corresponding tunnel segment, the second train automatically loads an enhanced monitoring strategy based on the warning information, marking high-risk segments and including the IP addresses and protocol types specified in the warning in the deep detection or direct filtering scope. When it receives suspicious commands from the same source again, it directly intercepts them.
[0067] Regarding the specific determination method for environmental-physical correlation verification, the system verifies whether the output power of the traction command matches the atmospheric pressure corresponding to the current altitude and the rated power of the traction motor. It also verifies whether the execution intensity of the braking command is suitable for the current track gradient, train load, and ambient temperature. If any of the above verifications fails, a level three alarm is triggered, and corresponding isolation and degraded operation measures are implemented.
[0068] Regarding the specific method for separating electromagnetic interference from attack characteristics, the system compares the normal noise baseline of the device under the current electromagnetic interference intensity and analyzes the synchronization relationship between abnormal characteristics and electromagnetic interference characteristics. If the abnormal characteristics and electromagnetic interference characteristics are synchronized, it is determined to be environmental interference and a level one alarm is triggered, with only logs being recorded and no isolation measures taken; if the abnormal characteristics and electromagnetic interference characteristics are not synchronized, it is determined to be a malicious network attack and a level two alarm is triggered, implementing port-level isolation and blocking of suspicious connections.
[0069] After completing the anomaly detection and response process, the system aggregates all log data generated in each step for subsequent adaptive learning. This log data includes environmental parameter records, anomaly detection results, response execution records, and manual review results. The system employs an online incremental learning algorithm to continuously optimize and iterate the dynamic baseline model under different altitudes, electromagnetic interference intensities, and geographical scenarios, constantly refining model parameters and detection thresholds. The updated baseline model is then fed back to the environmental perception and dynamic baseline generation stages, forming a complete closed-loop protection system. After completing the entire process, the system automatically returns to the steps of acquiring environmental parameters, electronic map data, and network monitoring data, continuously performing real-time data collection and security monitoring, thereby achieving all-weather, all-scenario, and adaptive operation of the high-altitude rail transit network security protection.
[0070] The above are some specific implementations of a rail transit network security protection method provided in the embodiments of this application. Based on this, this application also provides a corresponding device. The device provided in the embodiments of this application will be described below from the perspective of functional modularity.
[0071] Figure 5 This is a structural schematic diagram of a rail transit network security protection device provided as an embodiment of this application. (Combined with...) Figure 5 As shown, the rail transit network security protection device 500 provided in this application embodiment includes: The acquisition unit 510 is used to acquire environmental parameters, electronic map data and network monitoring data of the train's environment. The baseline generation unit 520 is used to generate an environment-adaptive baseline based on the environmental parameters and the electronic map data. The environment-adaptive baseline is used to dynamically adjust the judgment boundary of network security detection. Vector construction unit 530 is used to construct a multidimensional feature vector based on the environmental parameters and the network monitoring data; Anomaly detection unit 540 is used to perform multidimensional anomaly detection on the multidimensional feature vector based on the environmental adaptive baseline; The response execution unit 550 is used to execute a hierarchical response strategy in response to the anomaly detection result.
[0072] In one implementation of this application, the acquisition unit is specifically used to acquire at least one environmental parameter, including altitude, atmospheric pressure, ambient temperature, electromagnetic interference intensity, real-time location information of the train, and operating status. Acquire at least one type of electronic map data, including section identification and route feature information.
[0073] In one implementation of this application, the baseline generation unit is specifically used to dynamically adjust the sensitivity threshold of network traffic detection based on the intensity of electromagnetic interference. The normal fluctuation range of the sensor signal is corrected based on altitude and ambient temperature; A switching determination baseline for the location information source is generated based on the satellite signal strength, the segment identifier, and the real-time location.
[0074] In one implementation of this application, the vector construction unit is specifically used to perform spatiotemporal alignment of the environmental parameters, the network monitoring data, and the spatiotemporal features extracted from the electronic map data; Using timestamps and geographic locations as unified indexes, a multi-dimensional feature vector containing environmental features, spatiotemporal features, network features, control features, and feedback features is generated; The environmental characteristics include altitude, temperature, humidity, and electromagnetic interference intensity; The spatiotemporal features include the train's real-time location, section identifier, timestamp, and communication link status; The network characteristics include source IP address, destination IP address, protocol type, instruction content, traffic rate, and message interval. The control features include traction power commands, braking commands, and bogie control commands; The feedback features include traction current, brake cylinder pressure, speed, and acceleration.
[0075] In one implementation of this application, the anomaly detection unit is specifically used to call the environmental adaptive baseline as a dynamic judgment boundary, and sequentially perform spatiotemporal consistency verification, environmental-physical correlation verification, and electromagnetic interference and attack feature separation on the multidimensional feature vector.
[0076] In one implementation of this application, the step of calling the environmental adaptive baseline as a dynamic determination boundary and sequentially performing spatiotemporal consistency verification, environment-physical correlation verification, and electromagnetic interference and attack feature separation on the multidimensional feature vector includes: Perform the spatiotemporal consistency check. If the check fails, a level 3 alarm is triggered directly. If the check passes, continue to perform the environment-physical association check. Perform the environment-physical association verification. If the verification fails, trigger a level 3 alarm. If the verification passes, continue to perform the separation of electromagnetic interference and attack characteristics. The process involves separating electromagnetic interference from attack characteristics. If the interference is determined to be environmental interference, a Level 1 alarm is triggered. If the interference is determined to be malicious, a Level 2 alarm is triggered.
[0077] In one implementation of this application, the response execution unit is specifically used to record only abnormal event information when the first-level alarm is triggered; When the secondary alarm is triggered, the geographic coordination defense is triggered. If the communication link is interrupted, the attack characteristics and geographic segment number are cached locally and synchronized to the ground security management center after the communication link is restored. The ground security management center generates standardized early warning information and broadcasts it to subsequent trains, so that the subsequent trains can activate the enhanced monitoring strategy before entering the corresponding segment. When the Level 3 alarm is triggered, the connection between the attacked subsystem and the train network is cut off, triggering a degraded train safety operation. When the communication link is interrupted, the system switches to local autonomous protection mode, forcibly triggering geographically coordinated defense. The attack characteristics and geographical segment numbers are cached locally and synchronized to the ground safety management center after the communication link is restored. The ground safety management center generates standardized early warning information and broadcasts it to subsequent trains, enabling the subsequent trains to activate enhanced monitoring strategies before entering the corresponding segment.
[0078] In one implementation of this application, the step of performing the spatiotemporal consistency check, and directly triggering a level three alarm if the check fails, includes: When the train is running in a tunnel and the communication link is interrupted, if the spatiotemporal consistency check detects a remote command from the ground dispatch center, and the environment-physical correlation check detects that the power value of the remote command exceeds a preset percentage of the upper limit of the power model based on the current altitude, a level three alarm is triggered. At the same time, the traction control network interface is isolated, causing the traction controller to automatically switch to the local safe power curve and limit the speed to a preset safe value. A mandatory alarm prompt is issued to the driver, allowing the train to continue running until the next station for maintenance.
[0079] In one implementation of this application, the triggering of geographic coordination defense includes: When the first train detects a traction command tampering attack in a tunnel on the plateau line, an attack report containing attack characteristics and geographical segment number is generated and cached locally. After the first train exits the tunnel, the attack report will be uploaded to the ground security management center. The ground safety management center broadcast a warning message to the second train behind it. Before entering the corresponding tunnel section, the second train automatically loads an enhanced monitoring strategy based on the warning information, and directly intercepts the train when it receives a suspicious instruction from the same source again.
[0080] In one implementation of this application, the step of performing the environment-physical association verification and triggering a level three alarm if the verification fails includes: Verify whether the output power of the traction command matches the atmospheric pressure and rated power of the traction motor corresponding to the current altitude, and verify whether the execution intensity of the braking command is suitable for the current track gradient, train load and ambient temperature. If the verification fails, a level three alarm is triggered.
[0081] In one implementation of this application, the separation of electromagnetic interference and attack features includes: Compare with the normal noise baseline of the equipment under the current electromagnetic interference intensity; If the abnormal characteristics are synchronized with the electromagnetic interference characteristics, it is determined to be environmental interference and a level one alarm is triggered. If the abnormal characteristics are not synchronized with the electromagnetic interference characteristics, it is determined to be a malicious network attack and a level 2 alarm is triggered.
[0082] This application also provides corresponding devices and computer storage media for implementing the solutions provided in this application.
[0083] The device includes a memory and a processor. The memory stores instructions or code, and the processor executes the instructions or code to cause the device to perform the method described in any embodiment of this application.
[0084] The computer storage medium stores code, and when the code is run, the device running the code implements the method described in any embodiment of this application.
[0085] As can be seen from the above description of the embodiments, those skilled in the art can clearly understand that all or part of the steps in the methods of the above embodiments can be implemented by means of software plus a general-purpose hardware platform. Based on this understanding, the technical solution of this application can be embodied in the form of a software product. This computer software product can be stored in a storage medium, such as a read-only memory (ROM) / RAM, magnetic disk, optical disk, etc., including several instructions to cause a computer device (which may be a personal computer, a server, or a network communication device such as a router) to execute the methods described in various embodiments or some parts of the embodiments of this application.
[0086] It is understood that in the specific embodiments of this application, the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved need to obtain user permission or consent when the above embodiments of this application are applied to specific products or technologies, and the collection, use and processing of related data need to comply with the relevant laws, regulations and standards of relevant countries and regions.
[0087] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0088] It should also be noted that the various embodiments in this specification are described in a progressive manner, and the same or similar parts between the various embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, for the device and apparatus embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can be referred to the description of the method embodiments. The device and apparatus embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components indicated as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of the solution in this embodiment according to actual needs. Those skilled in the art can understand and implement this without creative effort.
[0089] The above description is merely one specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A method for protecting the network security of rail transit, characterized in that, The method includes: Acquire environmental parameters, electronic map data, and network monitoring data of the train's surroundings; An environmental adaptive baseline is generated based on the environmental parameters and the electronic map data. The environmental adaptive baseline is used to dynamically adjust the judgment boundary of network security detection. A multidimensional feature vector is constructed based on the environmental parameters and the network monitoring data; Based on the environmental adaptive baseline, multidimensional anomaly detection is performed on the multidimensional feature vector to obtain anomaly detection results; In response to anomaly detection results, a tiered response strategy is implemented, and a geographically based vehicle-to-ground-vehicle coordinated defense mechanism is triggered when an attack event is detected.
2. The method according to claim 1, characterized in that, Obtaining environmental parameters and electronic map data of the train's location includes: Acquire at least one environmental parameter, including altitude, atmospheric pressure, ambient temperature, electromagnetic interference intensity, real-time location information of the train, and operating status; Acquire at least one type of electronic map data, including section identification and route feature information.
3. The method according to claim 2, characterized in that, The process of generating an adaptive environmental baseline based on the environmental parameters and the electronic map data includes: The sensitivity threshold for network traffic detection is dynamically adjusted based on the intensity of electromagnetic interference. The normal fluctuation range of the sensor signal is corrected based on altitude and ambient temperature; A switching determination baseline for the location information source is generated based on the satellite signal strength, the segment identifier, and the real-time location.
4. The method according to claim 1, characterized in that, The construction of the multidimensional feature vector based on the environmental parameters and the network monitoring data includes: The environmental parameters, the network monitoring data, and the spatiotemporal features extracted from the electronic map data are spatiotemporally aligned. Using timestamps and geographic locations as unified indexes, a multi-dimensional feature vector containing environmental features, spatiotemporal features, network features, control features, and feedback features is generated; The environmental characteristics include altitude, temperature, humidity, and electromagnetic interference intensity; The spatiotemporal features include the train's real-time location, section identifier, timestamp, and communication link status; The network characteristics include source IP address, destination IP address, protocol type, instruction content, traffic rate, and message interval. The control features include traction power commands, braking commands, and bogie control commands; The feedback features include traction current, brake cylinder pressure, speed, and acceleration.
5. The method according to claim 1, characterized in that, The multidimensional anomaly detection based on the environmental adaptive baseline of the multidimensional feature vector includes: The environmental adaptive baseline is used as the dynamic decision boundary, and the spatiotemporal consistency verification, environment-physical correlation verification, and electromagnetic interference and attack feature separation are performed sequentially on the multidimensional feature vector.
6. The method according to claim 5, characterized in that, The step of calling the environmental adaptive baseline as the dynamic determination boundary and sequentially performing spatiotemporal consistency verification, environment-physical correlation verification, and electromagnetic interference and attack feature separation on the multidimensional feature vector includes: Perform the spatiotemporal consistency check. If the check fails, a level 3 alarm is triggered directly. If the check passes, continue to perform the environment-physical association check. Perform the environment-physical association verification. If the verification fails, trigger a level 3 alarm. If the verification passes, continue to perform the separation of electromagnetic interference and attack characteristics. The process involves separating electromagnetic interference from attack characteristics. If the interference is determined to be environmental interference, a Level 1 alarm is triggered. If the interference is determined to be malicious, a Level 2 alarm is triggered.
7. The method according to claim 6, characterized in that, The implementation of the hierarchical response strategy includes: When the Level 1 alarm is triggered, only abnormal event information is recorded; When the secondary alarm is triggered, the communication permissions of the affected network ports are restricted, and a vehicle-to-ground-to-vehicle coordinated defense mechanism based on geographical location is triggered. If the communication link is interrupted, the attack characteristics and geographical segment number are cached locally and synchronized to the ground security management center after the communication link is restored. The ground security management center generates standardized early warning information and broadcasts it to subsequent trains, so that the subsequent trains can activate the enhanced monitoring strategy before entering the corresponding segment. When the Level 3 alarm is triggered, the connection between the attacked subsystem and the train network is cut off, triggering a degraded train safety operation. When the communication link is interrupted, the system switches to a local autonomous protection mode, forcibly triggering a vehicle-to-ground-vehicle coordinated defense mechanism based on geographical location. The attack characteristics and geographical segment number are cached locally and synchronized to the ground safety management center after the communication link is restored. The ground safety management center generates standardized early warning information and broadcasts it to subsequent trains, enabling the subsequent trains to activate enhanced monitoring strategies before entering the corresponding segment.
8. The method according to claim 6, characterized in that, If the spatiotemporal consistency check fails, a level three alarm will be triggered directly, including: When the train is running in a tunnel and the communication link is interrupted, if the spatiotemporal consistency check detects a remote command from the ground dispatch center, and the environment-physical correlation check detects that the power value of the remote command exceeds a preset percentage of the upper limit of the power model based on the current altitude, a level three alarm is triggered. At the same time, the traction control network interface is isolated, causing the traction controller to automatically switch to the local safe power curve and limit the speed to a preset safe value. A mandatory alarm prompt is issued to the driver, allowing the train to continue running until the next station for maintenance.
9. The method according to claim 7, characterized in that, The triggered geographic coordination defense includes: When the first train detects a traction command tampering attack in a tunnel on the plateau line, an attack report containing attack characteristics and geographical segment number is generated and cached locally. After the first train exits the tunnel, the attack report will be uploaded to the ground security management center. The ground safety management center broadcast a warning message to the second train behind it. Before entering the corresponding tunnel section, the second train automatically loads an enhanced monitoring strategy based on the warning information, and directly intercepts the train when it receives a suspicious instruction from the same source again.
10. The method according to claim 6, characterized in that, If the environment-physical association verification fails, a level three alarm will be triggered, including: Verify whether the output power of the traction command matches the atmospheric pressure and rated power of the traction motor corresponding to the current altitude, and verify whether the execution intensity of the braking command is suitable for the current track gradient, train load and ambient temperature. If the verification fails, a level three alarm is triggered.
11. The method according to claim 6, characterized in that, The process of separating the electromagnetic interference from the attack signature includes: Compare with the normal noise baseline of the equipment under the current electromagnetic interference intensity; If the abnormal characteristics are synchronized with the electromagnetic interference characteristics, it is determined to be environmental interference and a level one alarm is triggered. If the abnormal characteristics are not synchronized with the electromagnetic interference characteristics, it is determined to be a malicious network attack and a level 2 alarm is triggered.
12. A network security protection device for rail transit, characterized in that, The device includes: The acquisition unit is used to acquire environmental parameters, electronic map data, and network monitoring data of the train's environment. The baseline generation unit is used to generate an environment-adaptive baseline based on the environmental parameters and the electronic map data. The environment-adaptive baseline is used to dynamically adjust the judgment boundary of network security detection. A vector construction unit is used to construct a multidimensional feature vector based on the environmental parameters and the network monitoring data; An anomaly detection unit is used to perform multidimensional anomaly detection on the multidimensional feature vector based on the environmental adaptive baseline. The response execution unit is used to respond to anomaly detection results, execute hierarchical response strategies, and trigger a geographically based vehicle-to-ground-vehicle coordinated defense mechanism when an attack event is detected.
13. A computing device, characterized in that, The computing device includes: a memory and a processor; The memory is used to store computer programs; The processor is configured to implement the steps of the rail transit network security protection method as described in any one of claims 1 to 11 when executing the computer program.
14. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the steps of the rail transit network security protection method as described in any one of claims 1 to 11.