基于网络靶场的重载铁路移动通信网络安全评测方法
DOI:
作者:
作者单位:

1.国能朔黄铁路发展有限责任公司;2.北京交通大学 宽带移动信息通信铁路行业重点实验室;3.北京交通大学 电子信息工程学院

作者简介:

通讯作者:

基金项目:

国能朔黄铁路发展有限责任公司科技项目(SHTL-23-32)

伦理声明:



Security evaluation method for heavy-duty railway mobile communication network based on cyber range
Author:
Ethical statement:

Affiliation:

1.CHN Energy Shuohuang Railway Development Co,Ltd;2.Key Laboratory of Railway Industryof Broadband Mobile Information Communications,Beijing Jiaotong University;3.School of Electronic and Information Engineering, Beijing Jiaotong University

Funding:

the project of CHN Energy Shuohuang Railway under Grant SHTL-23-32.

  • 摘要
  • |
  • 图/表
  • |
  • 访问统计
  • |
  • 参考文献
  • |
  • 相似文献
  • |
  • 引证文献
  • |
  • 资源附件
    摘要:

    随着重载铁路在货物运输中承担日益重要的角色,其宽带移动通信网络的安全性愈发关键。针对传统网络安全测试方法评测范围受限、资源消耗较大等局限性,创新性地引入网络靶场技术来进行重载铁路宽带移动通信网络安全评测。确定了数据链路层测试、接口测试、OAM系统安全测试、网络配置管理测试、性能压力测试、漏洞扫描与渗透测试和安全运维监控测试这7个重载铁路宽带移动通信网络安全评估指标,阐述了每一评估指标具体测试内容。利用网络靶场模拟真实环境,选取DDoS攻击、恶意软件攻击、身份认证攻击和网络延时攻击这4个实际运营中较为常见且具有代表性的典型场景进行测试。基于4种攻防场景下得到各网元及链路在攻击下CPU利用率、内存利用率、带宽、延迟、抖动和丢包率变化数据。最后使用层次分析法进行了网络风险评估,评估结果可为重载铁路网络安全性评估提供参考。

    Abstract:

    As heavy-haul railway plays an increasingly important role in cargo transportation, the security of their broadband mobile communication networks becomes more and more critical. Aiming at the limitations of traditional network security testing methods such as restricted evaluation scope and large resource consumption, cyber range technology is innovatively introduced to conduct the security evaluation of heavy-haul railway broadband mobile communication network. Seven security assessment indicators for the broadband mobile communication network of heavy-haul railways have been determined, including data link layer testing, interface testing, OAM system security testing, testing, OAM system security testing, network configuration management testing, performance pressure testing, vulnerability scanning and penetration testing, and security operation and maintenance monitoring testing. The specific testing contents of each assessment indicator are elaborated. The cyber range is used to simulate the real environment, and DDoS attacks, malware attacks, authentication attacks and network delay attacks are selected as the four typical scenarios that are more common and representative in actual operation for bandwidth, latency, jitter and packet loss rate changes of each network element and link under attack are obtained. Finally, the network risk assessment was carried out using the hierarchical analysis method, and the results can be used as a reference for the security assessment of heavy-duty railroad networks.

    参考文献
    相似文献
    引证文献
引用本文
分享
文章指标
  • 点击次数:
  • 下载次数:
  • HTML阅读次数:
历史
  • 收稿日期:2025-02-11
  • 最后修改日期:2025-03-17
  • 录用日期:2025-03-24
  • 在线发布日期:
  • 出版日期:
关闭