An Effective Intrusion Detection System Based on Network Traffic and Packets for CBTC

Xueqian Chen,Bing Bu,Xuetao Yang
DOI: https://doi.org/10.1007/978-981-15-2866-8_29
2019-01-01
Abstract:With the application of advanced network and computer technologies, communication-based train control (CBTC) systems are facing increasingly serious security risks. Intrusion detection can help detect attacks of CBTC systems and avoid major accidents. The traditional intrusion detection systems (IDS) do not consider the characteristics of CBTC systems, so they cannot be applied to CBTC systems directly. In this paper, we analyze the characteristics of network data of CBTC systems and propose an IDS based on network traffic and packets to detect typical attacks of CBTC systems, such as the denial of service (DoS) and data tempering attacks. The self-organizing maps (SOM) neural networks are used to improve the density-based spatial clustering of applications with noise (DBscan) method since DBscan only can detect anomalies offline with low detection rate. By testing on a simulation platform of CBTC systems, it is verified that the designed IDS is suitable for CBTC systems for its great detection performance and real-time performance.
What problem does this paper attempt to address?