The sophistication and complexity of cyber attacks and the variety of targeted platforms have been growing in recent years. Various adversaries are abusing an increasing range of platforms, e.g., enterprise platforms, mobile phones, PCs, transportation systems, and industrial control systems. In recent years, we have witnessed various cyber attacks on transportation systems, including attacks on ports, airports, and trains. It is only a matter of time before transportation systems become a more common target of cyber attackers. Due to the enormous potential damage inherent in attacking vehicles carrying many passengers and the lack of security measures applied in traditional airborne systems, the vulnerability of aircraft systems is one of the most concerning topics in the vehicle security domain. This paper provides a comprehensive review of aircraft systems and components and their various networks, emphasizing the cyber threats they are exposed to and the impact of a cyber attack on these components and networks and the essential capabilities of the aircraft. In addition, we present a comprehensive and in-depth taxonomy that standardizes the knowledge and understanding of cyber security in the avionics field from an adversary's perspective. The taxonomy divides techniques into relevant categories (tactics) reflecting the various phases of the adversarial attack lifecycle and maps existing attacks according to the MITRE ATT&CK methodology. Furthermore, we analyze the security risks among the various systems according to the potential threat actors and categorize the threats based on STRIDE threat model. Future work directions are presented as guidelines for industry and academia.
翻译:近些年来,网络袭击和各种定向平台的复杂程度和复杂性日益增长,各种对手滥用越来越多的平台,如企业平台、移动电话、个人计算机、运输系统和工业控制系统等,滥用了越来越多的平台,例如企业平台、移动电话、个人计算机、运输系统和工业控制系统。近年来,我们目睹了对运输系统的各种网络袭击,包括袭击港口、机场和火车;运输系统成为网络袭击者更常见的目标只是时间问题;由于袭击载运许多乘客的车辆所固有的巨大潜在损害,以及传统航空系统缺乏安全措施,飞机系统的脆弱性是车辆安全领域最关注的议题之一。本文全面审查了飞机系统及其部件及其各种网络,强调了它们面临的网络威胁,以及对这些组成部分和网络以及飞机基本能力发动的网络袭击所产生的影响。此外,我们还从对手的角度介绍了一个全面而深入的分类学,将网络安全模式领域的知识和理解标准化。 分类技术在相关类别(战术)中进行了区分,反映了航空器及其各种网络威胁的系统所面临的网络系统威胁。我们根据不同阶段,将现有的安全周期性风险分析系统,我们根据《亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-亚洲-