Return
Software-defined security based dynamic protection method for high-speed train network communications
DOI:10.1093/tse/tdag041.png)
Abstract
En 中文
The rapid expansion of high-speed railways enables the adoption of emerging control and communication technologies to address the increasing demands on train performance and safety. This advancement has intensified interconnectivity among the onboard devices, simultaneously introducing significant cybersecurity challenges. However, the flat, hierarchical network structure of high-speed trains brings challenges to deploying security equipment; embedded security measures are difficult to deploy to various terminal devices with limited resources. Consequently, a protection framework based on Software-Defined Security (SDSec) is proposed in this paper. Initially, it discusses how to dynamically reconfigure security resources to align with the onboard network architecture of high-speed trains. Then, a dynamic security protection method is proposed based on attack detection and security response, targeting the message transmission characteristics of the train control and monitoring system, the Structured State Space for Sequence (S4) model is employed to achieve attack detection and classification. The selection of appropriate security strategies to mitigate the impact of attacks is discussed, with system performance as the evaluation criterion. Finally, a simulation system, modeled on an actual train’s network topology and functional specifications, is constructed to verify the effectiveness of the proposed method.
Journal
T
IF:
3
Papers:
142
Citations:
560
Organization
Cited Papers
No cited papers available

