Back to news

May 22, 2020 | International, C4ISR, Security

Opinion: Aviation’s Cybersecurity Imperative

Remzi Seker May 22, 2020

With the expansion across the aviation industry of connectivity and computing services, cybersecurity has become ever more important. Connecting people, processes and assets creates new vulnerabilities and multiple attack points—from flight-critical avionics to passenger inflight entertainment networks and airline backend operations. Information about systems, protocols and technologies such as software-defined radio are now readily available well beyond the industry. Demand for greater efficiency meanwhile continues to increase connectivity and accelerate computerization within aviation infrastructure, including aircraft.

Fortunately, ongoing efforts to protect aircraft, airlines and passengers from cybersecurity threats have been largely unaffected by the global pandemic, suggesting an opportunity for the industry to ramp up cybersafety programs and training amid the current slowdown. The comprehensive, coordinated nature of aviation cybersecurity initiatives means committees have long carried out their work primarily through virtual meetings, so those efforts are able to continue in full swing. With slowdowns taking place in other areas, the industry can address cybersafety at a more rapid pace.

The aviation industry and its stakeholders have been working hard to tackle cybersecurity challenges comprehensively—from the supply chain and the maintenance of aircraft to operations. Such efforts remain essential so that cyberthreats affecting safety can be mitigated before they materialize, whether that happens during flight through physical access to a bus, by interfering with equipment through Wi-Fi or remotely disrupting operations.

The need to weigh cyberthreats according to their safety impact, a practice referred to as “cybersafety,” requires a different perspective than that of IT cybersecurity. Cybersafety differs from traditional IT cybersecurity because of the need for safety certification, which relies on guaranteeing a system's behavior, or “determinism.” This unique characteristic of aviation cybersafety means that solutions widely used across traditional computing systems may pose serious certification challenges. Imagine rolling out security patches for every avionics component on a commercial aircraft.

Tackling cybersafety challenges requires a coordinated, comprehensive, global effort. Multiple agencies are cooperating to establish much-needed standards. For example, the U.S. FAA and the European Union Aviation Safety Agency have been working with the RTCA and the European Organization for Civil Aviation Equipment to set harmonized cybersecurity standards.

Efforts to secure the aviation ecosystem also include dedicated committees such as the FAA's Aviation Rulemaking Advisory Committee Aircraft System Information Security/Protection working group. Similarly, the Aerospace Industries Association has established the Civil Aviation Cybersecurity Subcommittee.

In the U.S., the Aviation Cyber Initiative (ACI) is led by the Defense Department, Department of Homeland Security and FAA. The ACI includes experts representing government, defense, industry and academia who collaborate to tackle aviation cybersecurity threats. The Aviation Information Sharing and Analysis Center shares global threat intelligence among aviation companies.

Globally, the International Civil Aviation Organization (ICAO) leads this work. Its Trust Framework Study Group (TFSG) includes experts from the FAA, EASA, commercial industry and academia and has established three important working groups.

Academic institutions play a critical role in advancing cybersecurity research and training, too. Embry-Riddle Aeronautical University, for example, develops engineering solutions and provides degree, certification and training programs in aviation cybsersecurity. Faculty researchers contribute expertise to cyberdefense and preparedness efforts by serving on national and international committees and working groups and by organizing the annual Aero-Cybersecurity Symposium.

Aviation's impeccable safety culture positions it well to combat and defeat cybersafety risks. In the years ahead, the industry will need to invest in expanded education and training as well as research to secure high-assurance systems that can be updated with minimal impact on certification.

Computerization and Cyberphysical Systems

As computing becomes ever more affordable, functions that were traditionally implemented through hardware are now being realized through software, and inclusion of software has supported increased customization. Cyberphysical systems are designed to perform a set of functions with limited impact on the physical environment, such as temperature control, welding and parts assembly. One feature of cyberphysical systems is a failsafe property that involves shutting down—an approach that is clearly not desirable midflight.

Connectivity

Inexpensive and ubiquitously available computing, combined with advancements in networking, have accelerated the networking of devices. The Internet of Things concept does not require any form of certification or service-quality assurance, let alone any safety requirement or oversight. Rather than leveraging the Internet of Things, the aviation industry might consider using “networked wings” to underscore its safety commitment.

Remzi Seker is the associate provost for research at Embry-Riddle Aeronautical University.

The views expressed are not necessarily those of Aviation Week.

https://aviationweek.com/air-transport/safety-ops-regulation/opinion-aviations-cybersecurity-imperative

On the same subject

  • Indonesia says it wants to buy Austria’s entire Typhoon fighter fleet

    July 21, 2020 | International, Aerospace

    Indonesia says it wants to buy Austria’s entire Typhoon fighter fleet

    By: Mike Yeo MELBOURNE, Australia — Indonesia has expressed interest in acquiring Austria's fleet of Eurofighter Typhoon fighter jets, in yet another surprise defense procurement plan from the southeast Asian country. Indonesia's defense minister, Prabowo Subianto, wrote a letter to his Austrian counterpart, Klaudia Tanner, seeking to initiate negotiations to buy all 15 Typhoons belonging to the Austrian Air Force. In his letter, which was published by Indonesian news outlets, Prabowo said the potential purchase will assist in his aims to continue modernizing the Indonesian Air Force. He added that he understood the “sensitivity” of his proposal, which was likely to be a reference to the continued controversy surrounding Austria's 2002 acquisition of the Typhoon. That purchase has been dogged by questions about cost and the effectiveness of the aircraft. More recently, there have been allegations of corruption related to the original contract award. These culminated in Austria's 2017 decision to retire the aircraft from service this year in favor of a “more effective and cost-effective” solution for the central European country's air defense needs. Indonesia's interest in the fleet comes two weeks after the surprise announcement that the U.S. State Department cleared the country to buy the Bell-Boeing MV-22 tilt-rotor aircraft. Indonesia has been seeking a fighter aircraft to serve alongside its fleet of 23 refurbished early-block Lockheed Martin F-16C/D Fighting Falcon jets. These are all former aircraft operated by the U.S. Air National Guard, and were delivered from 2014 onward. The decision to seek the Austrian Typhoons, which are all Tranche 1 aircraft configured primarily for air defense missions, is a blow to Russian aspirations to sell the Sukhoi Su-35 Flanker interceptor to Indonesia. Indonesia had selected the Su-35 as its next fighter to provide continuity with its existing fleet of Su-27 and Su-30s Flankers acquired in the early part of the last decade. Negotiations for the Russian jets ended in 2018, but Indonesia had been reticent to sign the $1.14 billion contract, reportedly over fears that it may be subject to American sanctions. The sanctions would come from a U.S. law, Countering America's Adversaries Through Sanctions Act, that targets Iran, North Korea and Russia. CAATSA was passed by Congress in 2017 and is meant to discourage governments or entities from acquiring weapons or military hardware and parts from U.S. adversaries. https://www.defensenews.com/global/asia-pacific/2020/07/20/indonesia-says-it-wants-to-buy-austrias-entire-typhoon-fighter-fleet/

  • Europe's defense firms feel the squeeze of shortages, sanctions

    April 14, 2022 | International, Aerospace, Naval, Land, C4ISR, Security

    Europe's defense firms feel the squeeze of shortages, sanctions

    The aftermath of a yearslong pandemic and a protracted land war in Europe is causing defense contractors to take a serious look at how to sustain their supply chains.

  • Boeing wins bid for Germany's multibillion-dollar helo program

    June 2, 2022 | International, Aerospace

    Boeing wins bid for Germany's multibillion-dollar helo program

    The Chinook pick caps a yearslong saga for Germany to buy a new Schwerer Transporthubschrauber, or STH, as the heavy-lift chopper program is called in German.

All news