An Attack Tree-Based Approach for Vulnerability Assessment of Communication-Based Train Control Systems

Huiyu Dong,Hongwei Wang,Tao Tang
DOI: https://doi.org/10.1109/cac.2017.8243932
2017-01-01
Abstract:With the enhancement of informatization and automation, the capacity and efficiency of CBTC systems are increasing. However, the wide application of information technologies brings serious security threats on CBTC systems. Due to inherent characteristics of railway services, obtaining the security situation of CBTC systems is necessary. The methodlogy in this paper to evaluate the vulnerability of systems adopts attack tree modelling based on the functional architecture of CBTC systems. Assessments cover the current security states, port auditing, password policies and communication protocols of systems with the advantages of simplicity and operability. Based on the attack tree, leaf vulnerability, scenario vulnerability and system vulnerability are defined. During this assessment process, a typical scan tool, Nessus, and a vulnerability scoring system, CVSS, are used to achieve the port auditing. Moreover, a method to calculate the password strength and a piecewise linear function to normalize password strength are proposed. In the end, this approach is applied to a CBTC test-bed, and the assessment results show the difference of the vulnerability between the system with or without the improved countermeasures.
What problem does this paper attempt to address?