• 查询稿件
  • 获取最新论文
  • 知晓行业信息

面向APT攻击的铁路旅客服务与生产管控平台拟态防御架构与调度策略

CMD architecture and scheduling strategy for railway passenger service and production management control platform oriented to APT attack

  • 摘要: 铁路旅客服务与生产管控平台(简称:管控平台)是承载铁路客运车站(简称:客站)面向旅客服务与生产作业的重要平台。近年来,随着管控平台的快速发展,其因内部攻击面增大和外部未知攻击而产生的内生安全风险不断增加,为解决管控平台发展过程中的网络安全问题,文章基于博弈理论进行建模分析,提出了适配管控平台的面向APT(Advanced Persistent Threat)攻击的动态异构冗余(DHR,Dynamic Heterogeneous Redundancy)架构,以及一套适配该架构的调度策略。介绍了基于状态周期权重的冗余体调度(SCWS,State Cycle Weight Scheduling)算法,同时,进一步对SCWS算法性能进行了仿真实验,并在有限资源条件下对比该算法与相关算法的调度动态性与抗APT攻击的能力。实验证明了SCWS算法在该限定条件下其调度周期和抗APT攻击的次数明显优于其他几种算法。

     

    Abstract: The railway passenger service and production management and control platform (referred to as the management and control platform) is an important platform for railway passenger stations (referred to as passenger stations) to provide passenger services and production operations. In recent years, with the rapid development of management and control platforms, the endogenous security risks caused by the increase in internal attack surface and unknown external attacks have been constantly increasing. To solve the network security problems in the development process of management and control platforms, this paper modeled and analyzed based on game theory, and proposed a Dynamic Heterogeneous Redundancy (DHR) architecture for APT (Advanced Persistent Threat) attacks adapted to management and control platforms, as well as a scheduling strategy adapted to this architecture. The paper introduced the State Cycle Weight Scheduling (SCWS) algorithm based on redundant body scheduling, and conducted simulation experiments on the performance of SCWS algorithm, compared the scheduling dynamics and ability to resist APT attacks of this algorithm with related algorithms under limited resource conditions. The experiment shows that the SCWS algorithm has significantly better scheduling cycles and resistance to APT attacks than other algorithms under this constraint.

     

/

返回文章
返回