Securing the Future Railway System: Technology Forecast, Security Measures, and Research Demands

Simon Unger, Markus Heinrich, Dirk Scheuermann, Stefan Katzenbeisser, Max Schubert, Leon Hagemann, Lukas Iffländer
{"title":"Securing the Future Railway System: Technology Forecast, Security Measures, and Research Demands","authors":"Simon Unger, Markus Heinrich, Dirk Scheuermann, Stefan Katzenbeisser, Max Schubert, Leon Hagemann, Lukas Iffländer","doi":"10.3390/vehicles5040069","DOIUrl":null,"url":null,"abstract":"The railway industry—traditionally a conservative industry with low adaption speed for innovation—is currently entering its digitization phase. The sector faces a challenge in integrating new technologies and approaches into the employed—often safety-critical—systems. Keeping the systems secure while conforming to the demanding safety norms creates previously unknown problems. In the last decades, the number of attacks on the railway system has increased. Furthermore, with standardized digital technologies, the attack surface will keep growing. Therefore, in this work, we look into the foreseeable future of the railway system and present 21 likely use cases. We analyze these use cases regarding possible threats, rate the severity of these threats, and deduce and rate necessary countermeasures. To this end, we model these use cases and the corresponding threats and countermeasures using Attack Graphs. We use a graphical solution for the risk and security analysis due to advantages over other methods, i.e., table-based solutions, like simplified presentation and an easier understanding of relationships, dependencies, and interactions between various elements. From these Attack Graphs, we extracted 14 commonly recurring attack strategies. After analyzing 49 countermeasures regarding their current maturity and further research and standardization demands, we identified 21 in need of further investigation. This implies that 21 necessary countermeasures to secure these future use cases require further research to apply to railway systems or require standardization. These results will help researchers focus on the necessary research and standardization and railway operators to ensure the security of their systems.","PeriodicalId":73282,"journal":{"name":"IEEE Intelligent Vehicles Symposium. IEEE Intelligent Vehicles Symposium","volume":null,"pages":null},"PeriodicalIF":0.0000,"publicationDate":"2023-09-25","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"IEEE Intelligent Vehicles Symposium. IEEE Intelligent Vehicles Symposium","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.3390/vehicles5040069","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

The railway industry—traditionally a conservative industry with low adaption speed for innovation—is currently entering its digitization phase. The sector faces a challenge in integrating new technologies and approaches into the employed—often safety-critical—systems. Keeping the systems secure while conforming to the demanding safety norms creates previously unknown problems. In the last decades, the number of attacks on the railway system has increased. Furthermore, with standardized digital technologies, the attack surface will keep growing. Therefore, in this work, we look into the foreseeable future of the railway system and present 21 likely use cases. We analyze these use cases regarding possible threats, rate the severity of these threats, and deduce and rate necessary countermeasures. To this end, we model these use cases and the corresponding threats and countermeasures using Attack Graphs. We use a graphical solution for the risk and security analysis due to advantages over other methods, i.e., table-based solutions, like simplified presentation and an easier understanding of relationships, dependencies, and interactions between various elements. From these Attack Graphs, we extracted 14 commonly recurring attack strategies. After analyzing 49 countermeasures regarding their current maturity and further research and standardization demands, we identified 21 in need of further investigation. This implies that 21 necessary countermeasures to secure these future use cases require further research to apply to railway systems or require standardization. These results will help researchers focus on the necessary research and standardization and railway operators to ensure the security of their systems.
保障未来铁路系统安全:技术预测、安全措施与研究需求
铁路行业传统上是一个保守的行业,对创新的适应速度较低,目前正在进入数字化阶段。油气行业面临着将新技术和新方法整合到现有系统(通常是安全关键系统)中的挑战。在遵守严格的安全规范的同时保持系统的安全会产生以前未知的问题。在过去的几十年里,针对铁路系统的袭击数量有所增加。此外,随着标准化数字技术的发展,攻击面将不断扩大。因此,在这项工作中,我们展望了铁路系统可预见的未来,并提出了21个可能的用例。我们根据可能的威胁分析这些用例,评估这些威胁的严重性,并推断和评估必要的对策。为此,我们使用攻击图对这些用例以及相应的威胁和对策进行建模。我们使用图形解决方案进行风险和安全性分析,因为它比其他方法(即基于表的解决方案)有优势,比如简化的表示和更容易理解各种元素之间的关系、依赖关系和交互。从这些攻击图中,我们提取了14种常见的重复攻击策略。在分析了49种对策的成熟度和进一步的研究和标准化需求后,我们确定了21种需要进一步研究的对策。这意味着确保这些未来用例的21个必要对策需要进一步研究以应用于铁路系统或需要标准化。这些结果将有助于研究人员专注于必要的研究和标准化,以及铁路运营商确保其系统的安全性。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信