铁路系统APT攻击检测方法研究OA
Research on APT Attack Detection Method in Railway Systems
结合MITRE公司提出的对抗战术、技术和常识(Adversarial Tactics,Techniques,and Common Knowledge,ATT&CK)知识库和网络杀伤链模型,深入分析高级持续性威胁(Advanced Persistent Threat,APT)在铁路系统中的特点与生命周期,提出基于多维高斯型连续隐马尔可夫模型的APT攻击检测方法.该方法以主机系统CPU占有率、内存占有率、网络流量特征、安全设备告警信息及节点脆弱性度量作为观测序列,通过改进Viterbi算法实现对APT攻击状态准确识别.实验结果表明,该方法在侦察、武器化、交付、控制和行动5个攻击阶段均具备较高检测率和较低误报率,可有效识别APT攻击行为并实现及时预警,为铁路系统网络安全保障提供新的技术方案.
This paper combines the MITRE ATT&CK knowledge base and cyber kill chain model to thoroughly analyze the characteristics and lifecycle of Advanced Persistent Threat(APT)in railway systems,and proposes an APT attack detection method based on a multi-dimensional Gaussian continuous Hidden Markov Model(HMM).This method uses the CPU usage,memory usage,network traffic characteristics,security device alarm information,and node vulnerability metrics of the host system as observation sequences,to achieve the accurate identification of APT attack states through an improved Viterbi algorithm.The experimental results show that the proposed method demonstrates high detection rates and low false alarm rates across the five attack stages of reconnaissance,weaponization,delivery,control,and action,effectively identifying APT attack behaviors and providing timely warnings,and thus offering a new technical solution for ensuring network security in railway systems.
韩煜;李强;卢瑞铭
通号通信信息集团有限公司,北京 100070北京全路通信信号研究设计院集团有限公司,北京 100070北京全路通信信号研究设计院集团有限公司,北京 100070
交通工程
网络安全APT攻击检测隐马尔可夫模型
network securityAPT attack detectionhidden Markov model
《铁路通信信号工程技术》 2026 (6)
39-46,64,9
评论