Railway Interchange 2019

Safety and Security of Movable Rail Bridges (Room Auditorium)

23 Sep 19
8:30 AM - 9:00 AM

Tracks: AREMA Technical Sessions By Date- Communications & Signals, AREMA Technical Sessions By Functional Group- Communications & Signals, Technical Sessions By Day- Monday

This paper and propose a method to assess safety risks in the age on cyber activity for railroad operations. Most systems used in railroad control physical equipment using systems that are made from hardware and software, including communications and signaling. Most software and hardware systems have unforeseen vulnerabilities that can be exploited to cause service disruptions and degradations. These in turn can cause failures, resulting in unsafe operational conditions. Conversely, control systems have built in failure tolerant mechanisms (such as service degradations and terminations) that are called in response to impending or observed failures. An attacker that is aware of such mechanisms can exploit these designs to cause the triggering of service degradations and terminations, causing safety concerns. A motivated attacker can exploit the intertwined nature of these two phenomenon and create complex attacks that would cause unsafe operational conditions. We use fault-attack trees that model inter-twined ways of violating safety and cyber security objectives of a cyber-physical system design. By adding probabilistic estimates of fault rates, exploitability of known security vulnerabilities in existing equipment, attacker effort and capability estimates with kill-chains that have to be executed by potential misbehaving agents to cause safety and security concerns, we derive operational risks and cost-minimizing mitigations strategies against them. We show the capabilities of our methods by applying it to detailed models of movable railroad bridges and its effect on railroad operations. This work is, sponsored by FRA is done with the participation of railroads. *Missed this Session or want to view it again? Stop by the VirtualAREMA kiosk located in the Registration area to purchase this product today!