Ensuring the security of civil aviation infrastructure (CAI) is critical in a world where cyber threats are increasingly targeting critical systems, potentially impacting global aviation safety, operational continuity, and regulatory compliance. CAI includes essential sectors such as air traffic control, airport operations and communication networks. Disruptions to these systems can have far-reaching consequences, requiring effective approaches to identifying, assessing and managing cyber threats. Building on their previously developed universal method for managing IT threats in Critical Information Infrastructures (CII), the authors present an adapted method specifically tailored to the unique challenges of CAI. This method integrates the STRIDE threat identification model with the TODIM multi-criteria decision-making approach to enable systematic threat assessment and prioritization. The method also introduces a criticality variable to account for the varying importance of CAI components. Experimental validation across three CAI sub-sectors – communication networks, Air Traffic Control (ATC) systems, and Passenger Data Management Systems (PDMS) – demonstrated the method’s adaptability and effectiveness. The results identified Denial of Service (DoS) and Information Disclosure as critical threats, providing a robust framework for prioritizing risks and enhancing the cybersecurity of CAI.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Experimental Study of the Method for Cyber Incidents Management in Aviation Critical Infrastructure

  • Sergiy Gnatyuk,
  • Viktoria Sydorenko,
  • Artem Polozhentsev,
  • Serhii Sydorenko

摘要

Ensuring the security of civil aviation infrastructure (CAI) is critical in a world where cyber threats are increasingly targeting critical systems, potentially impacting global aviation safety, operational continuity, and regulatory compliance. CAI includes essential sectors such as air traffic control, airport operations and communication networks. Disruptions to these systems can have far-reaching consequences, requiring effective approaches to identifying, assessing and managing cyber threats. Building on their previously developed universal method for managing IT threats in Critical Information Infrastructures (CII), the authors present an adapted method specifically tailored to the unique challenges of CAI. This method integrates the STRIDE threat identification model with the TODIM multi-criteria decision-making approach to enable systematic threat assessment and prioritization. The method also introduces a criticality variable to account for the varying importance of CAI components. Experimental validation across three CAI sub-sectors – communication networks, Air Traffic Control (ATC) systems, and Passenger Data Management Systems (PDMS) – demonstrated the method’s adaptability and effectiveness. The results identified Denial of Service (DoS) and Information Disclosure as critical threats, providing a robust framework for prioritizing risks and enhancing the cybersecurity of CAI.