Hybrid Intrusion Detection with Decision Tree and Critical State Analysis for CBTC

Yajie Song,Bing Bu,Xuetao Yang
DOI: https://doi.org/10.1007/978-981-15-2914-6_16
2020-01-01
Abstract:Communication-based train control (CBTC) is considered as the main organ of urban rail transit systems, which is facing increasingly serious security threats. Intrusion detection systems (IDS) are crucial for security protection. This paper reports the design principles and evaluation results of a novel hybrid intrusion detection system which is suitable for CBTC systems. This hybrid method combines the advantages of the high true positive rate of network-based IDS (NIDS) and the ability of host-based IDS (HIDS) to monitor system behavior, where decision tree and critical state analysis are used, respectively. The proposed method is verified on a semi-physical simulation platform of CBTC and the experiments show that the designed scheme can detect intrusions accurately with a 97.8% detection rate.
What problem does this paper attempt to address?