Studying Cybersecurity in Civil Aviation, Including Developing and Applying Aviation Cybersecurity Risk Assessment

被引:16
作者
Elmarady, Ahmed Abdelwahab [1 ]
Rahouma, Kamel [2 ]
机构
[1] Minia Univ, Fac Engn, Al Minya 61519, Egypt
[2] Nahda Univ Beni Suef, Dept Comp Sci, Bani Suwayf 62511, Egypt
关键词
Computer security; Surveillance; Radio navigation; Risk management; Satellite navigation systems; Systematics; Aircraft navigation; Aeronautical communication systems; aeronautical surveillance systems; air navigation systems; cybersecurity; cybersecurity risk assessment; cyber resilience; radio navigation aids; system-wide information management (SWIM); SECURITY; VULNERABILITIES; SURVEILLANCE;
D O I
10.1109/ACCESS.2021.3121230
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In addition to the importance of safety in civil aviation, the significance of cybersecurity in the aviation sector cannot be ignored, and this fact has often been highlighted owing to frequent cyber-attacks that denigrate victim(s) and also lead to political and economic controversies. Cybersecurity has recently received a major boost, with the shift of air navigation facilities from analog ground-based systems to digital space-based systems to accommodate the tremendous growth in air traffic density. Furthermore, most air navigation facilities have open designs that tend to overlook security concerns. In this regard, identifying a systematic methodology for aviation cybersecurity risk assessment is a key element in the identification of potential threats, and assessment of their likelihood and risk levels, whereby risks can be reduced to tolerable levels through appropriate mitigation measures. Existing review articles have not addressed cybersecurity in all the various aviation systems, and have not considered a systematic methodology for aviation cybersecurity risk assessment. This paper therefore presents a systematic qualitative and quantitative cybersecurity risk assessment methodology for legacy and next-generation critical infrastructure in aviation systems, such as air-ground communication, radio navigation aids, aeronautical surveillance, and system-wide information management (SWIM). Our analysis shows that the communication, navigation, and surveillance systems with the highest risk levels are very-high frequency voice communication, satellite-based navigation, and automatic dependent surveillance-broadcast, respectively, while those with the lowest risk levels are controller-pilot data link communication, ground-based radio navigation aids, and secondary surveillance radar, respectively. Furthermore, the risk level of potential cyber-attacks in SWIM is medium.
引用
收藏
页码:143997 / 144016
页数:20
相关论文
共 82 条
[21]  
[Anonymous], 2018, ANNEX 10 AERONAUTICA, V1
[22]  
[Anonymous], 2017, 9849 ICAO, V3rd
[23]  
ARINC): 823-P1, 2007, 923P1 ARINC
[24]  
Cary T. F, 2017, DIGITAL AVIONICS HDB, V3rd
[25]   Security Testing with Controller-Pilot Data Link Communications [J].
Di Marco, Doris ;
Manzo, Alessandro ;
Hird, John ;
Ivaldi, Marco .
PROCEEDINGS OF 2016 11TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY, (ARES 2016), 2016, :526-531
[26]   Radar automatic target recognition using complex high-resolution range profiles [J].
Du, L. ;
Liu, H. ;
Bao, Z. ;
Zhang, J. .
IET RADAR SONAR AND NAVIGATION, 2007, 1 (01) :18-26
[27]   Actual TDoA-based augmentation system for enhancing cybersecurity in ADS-B [J].
Elmarady, Ahmed AbdelWahab ;
Rahouma, Kamel .
CHINESE JOURNAL OF AERONAUTICS, 2021, 34 (02) :217-228
[28]  
Evers C, 2010, PERFORMANCE ASSESSME
[29]   Enhancing the security of aircraft surveillance in the next generation air traffic control system [J].
Finke, Cindy ;
Butts, Jonathan ;
Mills, Robert ;
Grimaila, Michael .
INTERNATIONAL JOURNAL OF CRITICAL INFRASTRUCTURE PROTECTION, 2013, 6 (01) :3-11
[30]  
Frequentis A. G, 2018, P INT COMM NAV SURV