YekTrain
Vehicle systems on MVB and CANopen, built from recordings of real trains. Attacks and their detection can be shown on it reproducibly.
Built from the analysis of real trains. The advanced TrainLab of DB Systemtechnik and an ICE TD of class 605 provided real MVB implementations to IEC 61375, alongside analyses and security assessments of further vehicles from our testing work. From those we extracted signal definitions and timing behaviour and transferred them into two simulators. The vehicle systems sit on MVB and CANopen, with intrusion detection and a rail security operations centre running beside them.
You cannot practise on a train in service
Rail vehicles are type-approved systems with lifecycles measured in decades. You cannot try out on them what a forged telegram on the vehicle bus does. And yet that is exactly the question: what can someone with access to the vehicle communication achieve, and would anyone notice.
It is made harder by the fact that the Multifunction Vehicle Bus is standardised in IEC 61375 but the manufacturers implement it differently. Monitoring that understands only one variant is worthless in a mixed fleet.
Measure first, then build
The setup is derived from real recordings, not from a data sheet.
Recordings from real trains
The advanced TrainLab of DB Systemtechnik gave us a view of real MVB implementations; an ICE TD of class 605 served as the reference for complex topologies. Analyses and security assessments of further vehicles came on top. The authentic signal definitions and timing parameters come from there.
Two simulators
The physical train as a demonstration platform with an interactive dashboard you can operate. Beside it a virtual MVB simulator that implements the protocol fully in master-slave architecture, across nine safety-relevant vehicle systems from climate control and door control through traction and braking to safety systems and the driver-machine interface.
A vendor-neutral data basis
Recordings from two systems of different origin and our own virtual environment run through thin adapters into one uniform, IEC 61375-conformant data model. Only then can a rule be written that holds across a mixed fleet.
A compromised display unit that forges telegrams
For realistic threat scenarios we implemented the driver-machine interface as a compromised component. It can forge telegrams of other vehicle components and intervene through them: triggering an unplanned emergency brake and producing a false alarm from the fire detection system, by faking the corresponding safety telegrams.
This is not a constructed scenario. The bus has no sender check, and whoever may transmit on it can pose as any component. The setup confirms a fundamental weakness and shows at the same time why authentication and monitoring belong together here.
An IDS that genuinely understands the bus
Alongside the attack we developed intrusion detection for the vehicle bus. It decodes the different manufacturer variants, normalises them onto the common data model, enriches them with context and then works hybrid: rule-based for known patterns, learning-based for statistical deviation.
All components come together in a rail security operations centre of its own, which collects security events centrally, presents threats in real time and monitors the train live. The forged telegram is detected and reported on, and it is exactly that chain from intervention through detection to report that cannot be shown anywhere else.
The detection was validated against the real train recordings and against the virtual environment.
What we use the model for
For training and awareness among rail professionals. For security analysis in an environment where you may search without endangering an operation. For developing and testing detection methods, including their connection to an analysis platform. And as the stage before anything is tried on a type-approved vehicle.
What comes out of the model goes into our tests and into the security operations centres we have built for rail. And what stands out there comes back to the model.
See the demonstrator in action.
Wir zeigen die Anlage, die Angriffswege und was sich daran prüfen lässt.