Cyber security of railway cyber-physical system (CPS) – A risk management methodology

IF 12.5 Q1 TRANSPORTATION
Zezhou Wang, Xiang Liu
{"title":"Cyber security of railway cyber-physical system (CPS) – A risk management methodology","authors":"Zezhou Wang,&nbsp;Xiang Liu","doi":"10.1016/j.commtr.2022.100078","DOIUrl":null,"url":null,"abstract":"<div><p>Along with the increasing application of different cyber-physical systems (CPSs) to connect various components in the rail industry, rising connectivity through communication technologies has also introduced cyber threats against rail-CPSs, causing failures with huge consequences. Implementations of rail-CPSs demand proactive identification, clear-cut definition, and proper handling of their cyber security risks. In this paper, we formulate a risk management methodology for cyber security in rail-CPSs and conduct a retrospective case study on the Advanced Train Control System (ATCS) that has been deployed in many U.S. freight railways. The methodology provides two alternative approaches to fill knowledge gaps in contingency preparation, threat prevention, consequence analysis, and security risk mitigation. In the case study, we demonstrate two cyber threats of ATCS, using attack sequence modeling and consequence analysis, and provide recommendations for risk mitigation. By practicing the methodology with the case study, this work can be used as a general reference to conduct cyber risk management and cyber-robustness evaluations for other existing systems.</p></div>","PeriodicalId":100292,"journal":{"name":"Communications in Transportation Research","volume":"2 ","pages":"Article 100078"},"PeriodicalIF":12.5000,"publicationDate":"2022-12-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://www.sciencedirect.com/science/article/pii/S2772424722000282/pdfft?md5=cc9b39dcabf623bd5f32f3e511686205&pid=1-s2.0-S2772424722000282-main.pdf","citationCount":"11","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Communications in Transportation Research","FirstCategoryId":"1085","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S2772424722000282","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"TRANSPORTATION","Score":null,"Total":0}
引用次数: 11

Abstract

Along with the increasing application of different cyber-physical systems (CPSs) to connect various components in the rail industry, rising connectivity through communication technologies has also introduced cyber threats against rail-CPSs, causing failures with huge consequences. Implementations of rail-CPSs demand proactive identification, clear-cut definition, and proper handling of their cyber security risks. In this paper, we formulate a risk management methodology for cyber security in rail-CPSs and conduct a retrospective case study on the Advanced Train Control System (ATCS) that has been deployed in many U.S. freight railways. The methodology provides two alternative approaches to fill knowledge gaps in contingency preparation, threat prevention, consequence analysis, and security risk mitigation. In the case study, we demonstrate two cyber threats of ATCS, using attack sequence modeling and consequence analysis, and provide recommendations for risk mitigation. By practicing the methodology with the case study, this work can be used as a general reference to conduct cyber risk management and cyber-robustness evaluations for other existing systems.

铁路网络物理系统(CPS)的网络安全。风险管理方法
随着不同的网络物理系统(cps)越来越多地应用于连接铁路行业的各种组件,通过通信技术增加的连接性也引入了针对铁路cps的网络威胁,导致故障造成巨大后果。实施铁路cps需要主动识别,明确定义,妥善处理网络安全风险。在本文中,我们制定了铁路cps网络安全的风险管理方法,并对已在许多美国货运铁路中部署的先进列车控制系统(ATCS)进行了回顾性案例研究。该方法提供了两种替代方法来填补应急准备、威胁预防、后果分析和安全风险缓解方面的知识空白。在案例研究中,我们使用攻击序列建模和后果分析演示了ATCS的两种网络威胁,并提供了降低风险的建议。通过案例研究实践该方法,本工作可作为对其他现有系统进行网络风险管理和网络鲁棒性评估的一般参考。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
CiteScore
15.20
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信