中国铁道科学2024,Vol.45Issue(3) :128-137.DOI:10.3969/j.issn.1001-4632.2024.03.12

基于人工免疫的城轨列控系统信息安全态势评估方法

Research on Information Security Situation Assessment of Urban Rail Train Control System Based on Artificial Immune System

李其昌 步兵 赵骏逸 李刚
中国铁道科学2024,Vol.45Issue(3) :128-137.DOI:10.3969/j.issn.1001-4632.2024.03.12

基于人工免疫的城轨列控系统信息安全态势评估方法

Research on Information Security Situation Assessment of Urban Rail Train Control System Based on Artificial Immune System

李其昌 1步兵 2赵骏逸 2李刚3
扫码查看

作者信息

  • 1. 北京交通大学先进轨道交通自主运行全国重点实验室,北京 100044;中国铁道科学研究院集团有限公司通信信号研究所,北京 100081
  • 2. 北京交通大学先进轨道交通自主运行全国重点实验室,北京 100044
  • 3. 中国铁道科学研究院集团有限公司通信信号研究所,北京 100081
  • 折叠

摘要

针对城轨列控系统面临的信息安全风险日益突出的问题,提出基于人工免疫系统的态势评估(AIS-SA)方法,即利用城轨列控系统数据特性,设计检测器成熟机制和攻击检测方法,实时感知城轨列控系统遭受的网络攻击;设计检测器克隆和变异机制,进一步丰富检测器种群,提高城轨列控系统感知网络攻击的能力;仿真试验模拟城轨列控系统遭受不同强度身份认证拒绝服务攻击和TCP拒绝服务攻击,采用AIS-SA方法感知网络攻击并实时量化系统的安全态势.结果表明:AIS-SA方法感知网络攻击的能力较强,当检测器进化至25代时,对身份认证拒绝服务攻击的检测率为96.81%、误报率为0.25%,对TCP拒绝服务攻击的检测率为98.46%、误报率为1.32%,与其他方法相比检测率较高且误报率较低;此外,AIS-SA方法能表征不同攻击强度下城轨列控系统安全态势,当攻击强度增大时实时态势量化值升高,反之减小;仿真结果验证了AIS-SA方法的有效性和准确性.

Abstract

In view of the increasingly prominent information security risks faced by the urban rail train control system,an artificial immune system-based situation assessment(AIS-SA)method is proposed.Combined with the data characteristics of urban rail train control system,the mature mechanism of the detector and the cyber attack detection method are designed to sense the cyber attacks suffered by the urban rail train control system in real time.The mechanism of detector cloning and mutation is designed to further enrich the detector population and improve the ability of urban rail train control system to perceive cyber attacks.The simulation experiments simulate that the urban rail train control system is subjected to different intensity of identity authentication Dos attacks and TCP SYN Flood attacks.AIS-SA method is used to perceive the cyber attacks and quantify the security situation of the system in real time.The results show that AIS-SA method has a strong ability to perceive cyber attacks.When the detector evolves for 25 generations,the detection rate of identity authentication Dos attack is 96.81%,the false alarm rate is 0.25%,and the detection rate of TCP SYN Flood attack is 98.46%,and the false alarm rate is 1.32%.Compared with other methods,AIS-SA method has both high detection rates and low false positive rates.In addition,AIS-SA method can characterize the security situation of the urban rail train control system under different attack intensity.When the intensity of attack increases,the real time situation quantification value increases,and vice versa.Simulation results verify the effectiveness and accuracy of AIS-SA method.

关键词

城轨/列控系统/信息安全/态势评估/人工免疫/检测器

Key words

Urban rail/Train control system/Information security/Situation assessment/Artificial immunity system/Detector

引用本文复制引用

基金项目

北京市自然科学基金-丰台轨道交通前沿研究联合基金(L211002)

中国国家铁路集团有限公司科技研发计划(L2021G003)

北京交通大学先进轨道交通自主运行全国重点实验室自主课题(RAO2023ZZ004)

城市轨道交通北京实验室项目(I18H10010)

出版年

2024
中国铁道科学
中国铁道科学研究院

中国铁道科学

CSTPCD北大核心
影响因子:1.191
ISSN:1001-4632
段落导航相关论文