Skip to main content
QUICK REVIEW

[论文解读] Evaluating the Security of Aircraft Systems

Edan Habler, Ron Bitton|arXiv (Cornell University)|Sep 8, 2022
Information and Cyber Security被引用 5
一句话总结

本文提出了一套全面的、基于MITRE ATT&CK的航空器系统网络威胁分类法,通过STRIDE模型和攻击生命周期阶段分析航空电子系统各领域(ACD、AISD、PODD、PIESD)的漏洞。研究识别出空地通信、导航与监视系统中的关键攻击面,并提出未来研究方向,包括自主系统加固、网络响应中的人因因素,以及统一的威胁情报平台,以提升航空网络安全。

ABSTRACT

The sophistication and complexity of cyber attacks and the variety of targeted platforms have been growing in recent years. Various adversaries are abusing an increasing range of platforms, e.g., enterprise platforms, mobile phones, PCs, transportation systems, and industrial control systems. In recent years, we have witnessed various cyber attacks on transportation systems, including attacks on ports, airports, and trains. It is only a matter of time before transportation systems become a more common target of cyber attackers. Due to the enormous potential damage inherent in attacking vehicles carrying many passengers and the lack of security measures applied in traditional airborne systems, the vulnerability of aircraft systems is one of the most concerning topics in the vehicle security domain. This paper provides a comprehensive review of aircraft systems and components and their various networks, emphasizing the cyber threats they are exposed to and the impact of a cyber attack on these components and networks and the essential capabilities of the aircraft. In addition, we present a comprehensive and in-depth taxonomy that standardizes the knowledge and understanding of cyber security in the avionics field from an adversary's perspective. The taxonomy divides techniques into relevant categories (tactics) reflecting the various phases of the adversarial attack lifecycle and maps existing attacks according to the MITRE ATT&CK methodology. Furthermore, we analyze the security risks among the various systems according to the potential threat actors and categorize the threats based on STRIDE threat model. Future work directions are presented as guidelines for industry and academia.

研究动机与目标

  • 为解决航空电子系统中缺乏标准化、全面的网络威胁分类法,特别是从攻击者视角出发的问题。
  • 分析航空器系统在关键领域(ACD、AISD、PODD、PIESD)的安全态势,识别通信、导航与监视网络中的关键漏洞。
  • 通过将已知攻击映射至针对空中系统特异的攻击生命周期战术与技术,扩展MITRE ATT&CK框架以适用于航空领域。
  • 使用STRIDE模型对威胁进行分类,并基于潜在威胁参与者与系统关键性评估风险。
  • 提出未来研究方向,以加强自主飞行系统的安全性,提升飞行员对网络事件的响应能力,并开发统一的威胁情报平台,以增强航空业的网络安全。

提出的方法

  • 采用MITRE ATT&CK框架作为基础,并扩展其覆盖航空电子系统特异的攻击战术与技术,贯穿网络攻击生命周期。
  • 将已发表的航空器系统攻击案例(如ADS-B欺骗、ACARS利用)映射至扩展后的ATT&CK分类法,以验证其适用性。
  • 应用STRIDE威胁模型(欺骗、篡改、抵赖、信息泄露、拒绝服务、权限提升)对各系统组件的威胁进行系统性分类。
  • 根据ARINC 821标准,将航空器系统划分为四个领域:飞机控制领域(ACD)、航空公司信息服务领域(AISD)、乘客自有设备领域(PODD)和乘客信息与娱乐系统领域(PIESD)。
  • 开展领域级网络重叠与通信流分析,识别高风险集成点。
  • 提出统一的威胁情报平台(TIP),用于汇聚、组织并共享航空公司、机场与制造商之间的威胁数据,以提升集体防御能力。

实验结果

研究问题

  • RQ1如何扩展并适配MITRE ATT&CK框架,以建模针对航空器系统及其航空电子网络的特定网络威胁?
  • RQ2ARINC 821定义的四个航空器领域(ACD、AISD、PODD、PIESD)中的关键威胁向量与攻击面是什么?它们之间如何相互关联?
  • RQ3现有的航空电子系统网络攻击(如针对ADS-B或ACARS的攻击)如何与敌对攻击生命周期的各个阶段及STRIDE威胁模型相匹配?
  • RQ4当前自主飞行控制系统(如MCAS)的防御机制存在哪些关键缺口?如何加以弥补?
  • RQ5如何在航空生态系统中实现威胁情报的标准化共享,以提升主动防御与态势感知能力?

主要发现

  • 本文成功扩展MITRE ATT&CK框架,创建了针对航空电子网络威胁的领域专用分类法,实现了对攻击生命周期各阶段攻击技术的系统化分类。
  • 航空器系统极易受到商用现成(COTS)硬件与软件的攻击,ADS-B与ACARS系统的真实攻击案例已证明这一点。
  • STRIDE模型有效对航空电子组件的威胁进行了分类,揭示出拒绝服务与欺骗是导航与通信系统中最具威胁性的风险。
  • ACD与AISD领域网络风险尤为突出,因其在飞行控制与数据完整性中起关键作用,且存在显著的网络重叠与集成点,导致攻击面扩大。
  • 研究发现飞行机组缺乏实时、可解释的网络威胁信息,亟需基于人工智能的入侵检测系统,提供清晰、可操作的警报。
  • 提出统一的威胁情报平台(TIP)对跨利益相关方共享威胁数据至关重要,具有显著提升航空业集体网络安全韧性的潜力。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。