Assessing Aircraft Security: A Comprehensive Survey and Methodology for Evaluation

Author:

Habler Edan1ORCID,Bitton Ron1ORCID,Shabtai Asaf1ORCID

Affiliation:

1. Ben-Gurion University of the Negev, Israel

Abstract

The sophistication and complexity of cyber attacks and the variety of targeted platforms have grown in recent years. Adversaries are targeting a wide range of platforms, e.g., enterprise networks, mobile phones, PCs, and industrial control systems. The past few years have also seen various cyber attacks on transportation systems, including attacks on ports, trains, airports, and aircraft. Due to the enormous potential damage inherent in attacking vehicles carrying many passengers and the lack of security measures applied in existing airborne systems, the vulnerability of aircraft systems is one of the most concerning topics in the vehicle security domain. This article provides a comprehensive review of aircraft systems and components and their various networks, emphasizing the cyber threats they are exposed to and the impact of a cyber attack on these components and networks and an aircraft’s essential capabilities. In addition, we present a comprehensive and in-depth taxonomy that standardizes the knowledge and understanding of cyber security in the avionics field. The taxonomy divides attack techniques into relevant categories (tactics) reflecting the various phases of the adversarial attack lifecycle and maps existing attacks according to the MITRE ATT&CK methodology. To contribute to increased understanding of the potential risks, we categorize the identified threats related to the various systems based on STRIDE threat model and demonstrate the practical application of this taxonomy in the analysis of real-world attack use cases. Finally, we review various mitigation techniques aimed at addressing security risks related to aircraft systems. Future work directions are presented as guidelines for industry and academia.

Funder

Israeli Smart Transportation Research Center

Publisher

Association for Computing Machinery (ACM)

Subject

General Computer Science,Theoretical Computer Science

Reference131 articles.

1. 2017. How-secure-are-ifec-systems. Retrieved from http://interactive.aviationtoday.com/how-secure-are-ifec-systems/

2. Aircraft Communications Addressing and Reporting System. Retrieved from https://www.skybrary.aero/articles/aircraft-communications-addressing-and-reporting-system

3. ADSBRANGE. 2023. ADS-B Range. Retrieved from https://www.faa.gov/air_traffic/technology/adsb

4. Aerospace Village. 2020. DEF CON 28 Aerospace Village: Attacking Flight Management Systems. Retrieved from https://www.youtube.com/watch?v=G4dDRXBikvA

5. airbusskywise. 2023. Airbus Skywise - Industry Data Platform to Address Aircraft Operations Challenges. Retrieved from https://aircraft.airbus.com/en/services/enhance/skywise

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3