详细信息    本馆镜像全文|  推荐本文 |  |   获取CNKI官网全文
空中交通管理ATM(Air Traffic Management,简称:空管)系统是一个采用航空卫星、数据链和计算机网络等综合技术的复杂的智能化信息系统,它将航空通信、导航、监视和自动化设施联接起来,为机场、航空公司和航空器等提供气象、航行情报和空中交通管制ATC(Air Traffic Control)等方面的信息服务,保障航空交通运输的安全运行。
     本文将安全系统工程SSE(Systems Security Engineering)理论应用到空管系统的信息安全保障和评估中,结合系统动态控制DSC(Dynamic System Control)的思想,提出了空管系统信息安全保障的方法。主要的创新点如下:
     第三,提出了基于SAP的空管系统业务数据安全访问方法。针对空管系统业务数据库的安全访问,提出了基于安全访问路径SAP(Secure Access Path)的空管系统业务数据安全访问方法,防御和阻止各种恶意的入侵攻击。该方法在安全接入节点SN采用Diameter实现了空管安全系统的统一身份认证,为空管系统重点数据库的访问提供了信息安全保障。
The Air Traffic Management (ATM) system is an open and complex intelligent system, which links the infrastructures and technologies of aeronautic communication, navigation, surveillance, and automation together to provides aeronautic information, aeronautical meteorology, and air traffic control (ATC) services to the airport, airlines, and aircraft. The targets of ATM system are enabling safe, orderly and efficient aircraft operations.
     An approach of information Assurance for ATM system based on Systems Security Engineering (SSE) theory is proposed in this thesis. The innovations in this thesis are as follows.
     (i) The model of security evaluation for information assurance of ATM system based on the theory of Dynamic System Control (DSC). This thesis established the theory of security evaluation for ATM system from the three views of function, operation, and attribution. The security indicator for information assurance of ATM system is proposed based on the security baseline policy. This theory is composed of security evaluate model based on DSC theory for the purpose of determine the security level of ATM element.
     (ii) The method of security evaluation for ATM system based on Artificial Neural Network. This thesis application of integrated decision making in ATM system based on grey correlation theory to solve the fuzzy relationship among a lot of complicated factors in ATM system. The security evaluation method of ATM system based on improved BP and RBF model of Artificial Neural Network (ANN) is proposed in this thesis. Test result shows that the proposed method meets the requirements of ATM information security and efficient to the information assurance of ATM system.
     (iii) The secure approach of operational data in ATM system based on Security Access Path (SAP). The thesis proposes a database secure access approach of operational data in ATM system based on SAP, which could effectively identify users, carry access control, and resist kinds of attacks with the uniform authentication based on diameter.
     Experiments on information security of ATM system with practical operation data of ATM system have conducted. Result shows that the proposed approach in this thesis is effectively.
    [2] 2006-2020年国家信息化发展战略[D],中共中央办公厅,国务院办公厅. 2006,(06): 1-28.
    [5]中国航空运输发展报告(2007/2008) ,中国民航局,http://www.caac.gov.cn/H1/
    [7] C. E. Shannon,Communication theory of secrecy systems,Bell System Technical Journal, 1949,28(4):656-715.
    [8] Debar.M.Becket and D.Sibon,A Neural Network Componem lop an Intrusion Detection Syitem,Proc.I 992 IEEE Computer Society Symposium,Research in Computer&curity and Privacy,Oakland.May 1 092.240--250.
    [9] Venter H S,Vulnerability forecasting-A conceptual model[J].Computers and Security,2004,(23):489-497.
    [10]侯小梅,毛宗源,基于P2DR模型的Internet安全技术,计算机工程与应用,2000, 23:1-2.
    [11] Keith A. Rhodes, Public Key Infrastructure: Examples of Risks and Internal Control Objectives Associated with Certification Authorities [R], GAO, August 2004
    [18]Information Systems Security (ISS). Federal Aviation Administration (FAA), Information Technology (IT), Research and Development (R&D) Workshop[T], 2008, 1-7.
    [19]Arthur Pyster. A Systems Approach to Protecting the U.S. Air Traffic Control System Against Cyber-Terrorism [T]. Federal Aviation Administration. 2004.
    [25]吴志军,杨义先,信息化进程的研究,计算机科学(2008年核心),第37卷第4期,2010年4月1日. P. 11-14.
    [29]温涛,中国人民银行计算机信息安全管理的问题与对策研究,重庆大学硕士论文, 2008年4月.
    [34]Marshall D. Abrams. FAA System Security Testing and Evaluation. Mitre Technical Report: MTR 02W0000059. May 2003.
    [38]Arinc Specification 823P1: Datalink Security Part 1-ACARS Message Security. An Document Prepared by AEEC Published by Aeronautical Radio, INC. 2551 Riva Road, Annapolis, Maryland 21401-7435. Published: December 10, 2007.
    [39] Arinc Specification 823P1: Datalink Security Part 2–Key Management. An Document Prepared by AEEC Published by Aeronautical Radio, INC. 2551 Riva Road, Annapolis, Maryland 21401-7435. Published: March 10, 2008.
    [48]Patel, V.; McParland, T.; Public key infrastructure for air traffic management systems . Digital Avionics Systems, 2001. DASC. The 20th Conference Volume: 2 Digital Object Identifier: 10.1109/DASC.2001.964185. 2001, Page(s): 7A5/1 - 7A5/7 vol.2.
    [49][美]Carlisle Adams,Steve Lloyd.冯登国等译,公开密钥基础设施-概念、标准和实施,人民邮电出版社,2001年1月.
    [50]Michael L. Olive. Efficient Datalink Security in A Bandwidth-Limited Mobile Environment - an Overview of the Aeronautical Telecommunications Network (ATN) Security Concept. IEEE Conference. Honeywell International Inc., Columbia, Maryland. 2001.
    [51]Carnegie Mellon University. Systems Security Engineering Capability Maturity Model“SSE-CMM”Model Description Document Version 3.0, June 15, 2003
    [52]中华人民共和国国家标准,信息技术安全技术信息技术安全性评估准则第一部分:简介和一般模型. GB/T 18336.1-2001 idt ISO/IEC 15408-1:1999.国家质量技术监督局. 2001年3月发布.
    [53]潘雯,民航空管系统安全性评价指标体系的研究.中国民航大学,硕士论文. 2008年.
    [54]赵文,信息安全保障综合度量及综合评价研究[博士学位论文].四川:四川大学数学学院, 2000年.
    [60]吴志军,杨义先,信息安全保障评价指标体系的研究,计算机科学(2008年核心),第37卷7期. 2010年7月1日.p.7-10
    [67] Port, D.; Kazman, R.; Takenaka, A.; Strategic Planning for Information Security and Assurance. Information Security and Assurance, 2008. ISA 2008. International Conference on. 2008. Page(s): 466– 471.
    [70]信息系统安全等级保护定级指南[EB/OL]. http://www.isra.infosec.org.cn/pgbz/RAstand/200604/1161.html,2006-04-11
    [71]信息系统安全等级保护测评准则[EB/OL]. http://www.isra.infosec.org.cn/pgbz/RAstand/200604/1163.html,2006-04-11
    [72]信息安全技术信息系统安全等级保护基本要求[EB/OL]. http://www.chinaeclaw.com/readArticle.asp?id=9838,2007-04-26
    [82]MA Lan, LI Gang, and GAO Wei. State Observer Based Adaptive Information Assurance Evaluation Model. Proceedings of 2010 IEEE International Conference on Wireless Communications, Networking and Information Security. Vol. 2. June 25-27, 2010, Beijing, China. pp. 173-178.
    [83]申健.网络安全综合评估方法的研究及应用[D].兰州大学无线电物理系, 2005年.
    [84]赵冬梅,刘海峰,张军鹏.基于模糊神经网络的信息安全风险评估模型[J],计算机工程与应用, 2009, 45(17), p.116-118.
    [85]Dong-Mei Zhao, Jin-Xing Liu, Ze-Hong Zhang. Method of risk evaluation of information security based on neural networks[C], Machine Learning and Cybernetics, 2009 International Co-nference on Volume: 2, 2009, p. 1127 - 1132.
    [86]于群,冯玲.基于BP神经网络的网络安全评价方法研究[J],计算机工程与设计. 2008,29(8):1963-1966.
    [88] Simon Haykin. Neural Networks and Learning Machines (3rd Edition). Prentice Hall. ISBN:0131471392. Nov. 2008.
    [91]刘海燕,王维锋,蔡红柳.一个基于神经网络的信息系统安全性综合评估模型[J],计算机工程与科学,2008, 30(11), p. 16-18.
    [93]任伟,蒋兴浩,孙锬锋,基于RBF神经网络的网络安全态势预测方法[J],计算机工程与应用,2006. 42(31).p. 136-144.
    [97]马兰,彭越,基于AMP的ATM信息安全在线评估系统的研究.计算机应用与软件(全国中文核心期刊1992~2008). 2011年第28卷第3期,2011年3月.
    [98]Keromytis A D, Misra V, Rubenstein D. SOS: An Architecture for Mitigating DDoS Attacks[J]. IEEE Journal on Selected Areas in Communications,2004,22(1): 176-188.
    [99]Ma, Lan, Yan, Hanming, and Jin, Zonghui. The secure approach of accessing to the kernel database in state key information system. Proceedings - 2010 IEEE International Conference on Wireless Communications, Networking and Information Security, WCNIS 2010. June 25, 2010 - June 27, 2010. Beijing, China. (EI收录:20104113284096)
    [101] Christopher Metz.,AAA Protocols:Authentication,Authorization,and Accounting for the Internet[J].IEEE Internet Computing, November December 1999
    [102]Djuric D, Dobrijevic O, Huljenic D, et al. Open Diameter Conformance Testing[J]. 6th International Symposium on Communication Systems, Networks and Digital Signal Processing [C]. Graz, 2008.124-128.
    [103]Wei D, Liu Y H, Yu X G, et al. Research of Mobile IPv6 Application Based On Diameter Protocol[J]. First International Multi-Symposiums on Computer and Computational Sciences[C]. Hangzhou, China, 2006.25-29.