基于网络靶场的重载铁路移动通信网络安全评测方法
作者:
作者单位:

1.国能朔黄铁路发展有限责任公司,河北 肃宁 062350;2.北京交通大学,宽带移动信息通信铁路行业重点实验室;3.北京市高速铁路宽带移动通信工程技术研究中心,北京 100044;4.电子信息工程学院,北京 100044

作者简介:

谢克绪(1981-),男,硕士,高级工程师,主要研究方向为铁路通信.email:11074726@chnenergy.com.cn.
孙 斌(1981-),男,硕士,助理研究员,主要研究方向为宽带移动通信与专用移动通信.
王丽鑫(2002-),女,在读硕士研究生,主要研究方向为宽带移动通信与专用移动通信.
冯 源(1998-),男,在读博士研究生,主要研究方向为算力网络、无线通信安全.
刘 腾(2001-),男,在读博士研究生,主要研究方向为人工智能安全.
丁建文(1980-),男,博士,研究员,主要研究方向为宽带移动通信与专用移动通信.

通讯作者:

孙 斌 email:bsun@bjtu.edu.cn

基金项目:

国能朔黄铁路发展有限责任公司科技资助项目(SHTL?23?32)

伦理声明:



Security evaluation method for heavy-duty railway mobile communication network based on cyber range
Author:
Ethical statement:

Affiliation:

1.CHN Energy Shuohuang Railway Development Co.,Ltd.,Suning Hebei 062350,China;2.a.Key Laboratory of Railway Industry of Broadband Mobile Information Communications;3.b.Beijing Engineering Research Center of High-speed Railway Broadband Mobile Communications;4.cSchool of Electronic and Information Engineering,Beijing Jiaotong University,Beijing 100044,China

Funding:

  • 摘要
  • |
  • 图/表
  • |
  • 访问统计
  • |
  • 参考文献
  • |
  • 相似文献
  • |
  • 引证文献
  • |
  • 资源附件
    摘要:

    随着重载铁路在货物运输中承担日益重要的角色,其宽带移动通信网络的安全性愈发关键。针对传统网络安全测试方法存在评测范围受限、资源消耗较大等局限性,创新性地引入网络靶场技术,用于重载铁路宽带移动通信网络安全评测。确定了数据链路层测试、接口测试、操作、管理和维护(OAM)系统安全测试、网络配置管理测试、性能压力测试、漏洞扫描与渗透测试和安全运维监控测试这7个重载铁路宽带移动通信网络安全评估指标,阐述了每一评估指标具体测试内容。利用网络靶场模拟真实环境,选取分布式拒绝服务攻击(DDoS)、恶意软件攻击、身份认证攻击和网络延时攻击这4个实际运营中较为常见且具有代表性的典型场景进行测试。基于4种攻防场景下得到各网元及链路在攻击下中央处理器(CPU)利用率、内存利用率、带宽、延迟、抖动和丢包率变化数据。最后使用层次分析法进行了网络风险评估,评估结果可为重载铁路网络安全性评估提供参考。

    Abstract:

    As heavy-haul railway plays an increasingly important role in cargo transportation, the security of their broadband mobile communication networks becomes more and more critical. Aiming at the limitations of traditional network security testing methods such as restricted evaluation scope and large resource consumption, cyber range technology is innovatively introduced to conduct the security evaluation of heavy-haul railway broadband mobile communication network. Seven security assessment indicators for the broadband mobile communication network of heavy-haul railways have been determined, including data link layer testing, interface testing, Operation, Administration, and Maintenance(OAM) system security testing, network, configuration management testing, performance pressure testing, vulnerability scanning and penetration testing, and security operation and maintenance monitoring testing. The specific testing contents of each assessment indicator are elaborated. The cyber range is employed to simulate the real environment, and Distributed Denial of Service(DDoS) attacks, malware attacks, authentication attacks and network delay attacks are selected as the four typical scenarios that are more common and representative in actual operation for testing. Based on the four attack and defense scenarios, the data of Central Processing Unit(CPU) utilization, memory utilization, bandwidth, latency, jitter and packet loss rate changes of each network element and link under attack are obtained. Finally, the network risk assessment is carried out using the hierarchical analysis method, and the results can be used as a reference for the security assessment of heavy-duty railroad networks.

    参考文献
    相似文献
    引证文献
引用本文

谢克绪,孙斌,王丽鑫,冯源,刘腾,丁建文.基于网络靶场的重载铁路移动通信网络安全评测方法[J].太赫兹科学与电子信息学报,2025,23(12):1239~1249

复制
分享
文章指标
  • 点击次数:
  • 下载次数:
  • HTML阅读次数:
历史
  • 收稿日期:2025-02-11
  • 最后修改日期:2025-03-17
  • 录用日期:
  • 在线发布日期: 2026-02-13
  • 出版日期:
关闭