Research Paper: Safeguarding Skies: Airport Cybersecurity in the Digital Age
Safeguarding Skies: Airport Cybersecurity in the Digital Age Suphannee Sivakorn*, Nuttaya Rujiratanapat*, Yotsapat Ruangpaisarn*, Chanond Duangpayap* and Sakulchai Saramat* Received: March 6, 2024 Revised: November 16, 2024 Accepted: November 25, 2024 * Corresponding Author: Suphannee Sivakorn, E-mail: [email protected] DOI: 10.14416/j.it/2025.v2.005
Abstract
ensure their security practices meet current standards.
The aviation industry faces significant vulnerabilities
However, in the realm of technology, cybersecurity often receives
from both physical and cybersecurity threats, highlighting
inadequate attention than physical security, as evidenced by
the urgent need for enhanced cybersecurity measures amid
a 2017 survey of the top major airports in Europe and the U.S.,
increasingly sophisticated attacks. This paper systematically
wherein only 59% of respondents claimed to have an effective
reviews emerging threats at airports, analyzing real-world
cybersecurity policy [1]. This oversight is concerning,
incidents and relevant literature while mapping risks to
especially given a 530% increase in cyberattacks within
the MITRE ATT&CK Matrix, a widely recognized knowledge
the aviation industry from 2019 to 2022 [2]. Recent initiatives
base for categorizing cyberattack tactics, techniques,
by authorities, including the Transportation Security
and procedures. This is the first to apply the MITRE Matrix to
Administration (TSA) and the International Air Transport
airport security risks, offering a novel approach to understanding
Association (IATA), emphasize the need for enhanced
and mitigating these challenges. Building on this analysis,
cybersecurity measures, mandating proactive steps to mitigate
the paper advocates for modern cybersecurity defense models,
cyber threats [3], [4].
emphasizing Cybersecurity Frameworks and Zero Trust
In an effort to strengthen the cybersecurity posture of
Architecture, as well as critical measures for supply chain
the aviation industry, this study comprehensively explores
risk management and strategies to mitigate ransomware and
existing literature and recent data on airport cybersecurity.
DoS attacks. Our analysis provides insights into vulnerabilities
We examine airport technologies, security concerns,
and actionable recommendations, serving as a comprehensive
and recent cyber incidents in Section 2, and outline our research
guide for aviation stakeholders to strengthen defenses against
methodology in Section 3. Section 4 presents a systematic
evolving cybersecurity threats.
literature review of airport cybersecurity from the past five years, and Section 5 categorizes the current landscape and identifies
Keywords: Airport Cybersecurity, Aviation Cybersecurity,
relevant risks. We map these risks to the MITRE ATT&CK
Cyber Threats in Aviation, Critical Infrastructure, Smart Airport.
Matrix for Enterprise, a widely recognized cybersecurity knowledge base for developing effective security strategies in
1. Introduction
Section 6. Section 7 presents modern cybersecurity defense
In the physical domain, airport security entails the screening
strategies, advocating for Cybersecurity Frameworks and
of passengers, baggage, cargo, and the fortification of secure
Zero Trust Architecture and highlights essential measures
areas within the airport premises. Airport authorities undertake
for mitigating supply chain risks, ransomware, and denial-of-
substantial efforts to prevent unlawful interference and
service (DoS) attack. Section 8 discusses key challenges
* Department of Computer Science, Faculty of Science and Technology, Rajamangala University of Technology Tawan-ok
ปีี ที่่� 21 ฉบัับที่่� 2 กรกฎาคม - ธัันวาคม 2568
Vol. 21, No. 2, July - December 2025
วารสารเทคโนโลยีีสารสนเทศ มจพ. 47
Information Technology Journal KMUTNB
Research Paper: Safeguarding Skies: Airport Cybersecurity in the Digital Age
and outlines future research directions in this field, with
Airport 3.0 or "Smart Airport" integrates the Internet
the conclusion presented in Section 9.
of Things (IoT), Artificial Intelligence, smart sensors to
The major contributions of this paper are as follows:
enhance passenger experience [8].
•
We conducted an extensive analysis of recent
Airport 4.0 emphasizes the use of technologies to support
cyberattacks and a literature review from the past
airport operations and enhance passenger experiences,
five years, categorizing key cybersecurity risks
with a focus on data analytics as a core capability [9], [10].
into nine distinct areas to clarify the challenges
While these airport advancements offer notable benefits,
faced by modern airport operations.
they are susceptible to interference and malicious modification
•
We correlate these identified risks with the MITRE
without proper deployment.
ATT&CK Matrix for Enterprise, making this paper
2.2 Airport Cyber Threat Actors
the first to map airport security risks to the Matrix.
Incidents of air terrorism have led adversaries to adapt
This serves as a valuable tool for exploring each
their tactics in both physical and cyber domains [7].
risk through practical defenses and best practices
This section outlines four types of cyber threat actors:
outlined in the MITRE knowledge base.
1: Advanced Persistent Threat (APT): Organized groups
•
Based on our analysis, we advocate for adopting
or foreign governments motivated by political or economic goals.
modern security practices, including Cybersecurity
They often target critical infrastructure, including airports
Frameworks and Zero Trust Architecture, along
[11] - [16].
with practical measures to defend against evolving
airport cyber threats.
2: Cybercrime: Attackers in this category target systems for valuable and sensitive information from passengers and airport employees [17] - [21], particularly those that are
2. Background
internet-facing or publicly accessible [17].
Understanding airport technologies, threat actors,
3: Peer Group Service Disruption: Hackers motivated by
and recent high-profile incidents highlights the need for stronger
political agendas or beliefs whose focus is on service disruptions
security measures. This section examines airport technology,
rather than data theft and financial gain [22] - [30].
cybersecurity concerns, the landscape of cyber threat actors, and notable attack incidents.
4: Insider Threats: Risks that originate from within the organization, typically associated with current or former
2.1 Airport Technology and Security Concerns
members of the organization, it may also arise from third parties
Airport operations have transformed significantly to support
such as contractors and temporary workers.
the global aviation industry growth, leading to advancements in
2.3 Recent Notable Cybersecurity Incidents
technology aimed at enhancing efficiency and service.
The urgency of cybersecurity in airports has become
The evolution of airport technology is delineated into four stages:
apparent through numerous studies [1], [5], [8]. From 2022
Airport 1.0 - 4.0.
to 2024, various notable incidents have highlighted cyberattacks
Airport 1.0 primarily focuses on ensuring the physical safety of operations, with no security concerns [5].
affecting airport operations and public perception. Table 1 details and categorizes these incidents by attack type,
Airport 2.0 incorporates technologies for collaboration
including Denial-of-Service, Ransomware, Vulnerability
technologies such as IP telephony, broadband, and Wi-Fi [6].
Exploitation, and Phishing. This analysis will assist in identifying
Following the events of 9/11, the TSA was established to
cybersecurity risks and associated attack vectors for airports
oversee transport security [7].
in Section 5.
48 วารสารเทคโนโลยีีสารสนเทศ มจพ.
Information Technology Journal KMUTNB
ปีี ที่่� 21 ฉบัับที่่� 2 กรกฎาคม - ธัันวาคม 2568 Vol. 21, No. 2, July - December 2025
Research Paper: Safeguarding Skies: Airport Cybersecurity in the Digital Age
Denial-of-Service (DoS). Recently, several major
4. Literature Review
U.S. airports were targeted by coordinated DoS attacks [29],
We conduct a comprehensive literature review by searching
which overloaded airport servers. Similar incidents have
academic databases, including Google Scholar, ResearchGate,
occurred at various airports worldwide [23] - [31]. In some
Scopus, and Web of Science, using the following keywords:
cases, attackers have demanded cryptocurrency payments to
"airport AND cybersecurity", "aviation AND cybersecurity",
stop the attacks, exploiting the difficulty of tracing such
"airport AND information security", "airport AND IT security",
transactions [32].
"smart airport", and "airport AND cyber risk". Our focus
Ransomware. The airport industry has experienced
was on peer-reviewed studies from the last five years addressing
a significant increase in ransomware attacks, primarily due to
the impacts of cybersecurity on modern airports, challenges,
system vulnerabilities and phishing attempts [33] - [35], [38].
and risks, while excluding studies on airport physical security
In 2024, notable incidents led to delays in passenger processing
or unrelated aviation topics. In total, we reviewed 31 publications,
and flight schedules [34], [35], while others resulted in
categorizing them into eight primary areas: (1) Critical
the leakage of sensitive data [33].
Infrastructure, (2) IoT, Smart Devices, and AI Technology,
Vulnerability Exploitation poses significant risks for
(3) Supply Chain, (4) Cybersecurity Awareness, (5) Risk
airports, which rely on variety of software applications for their
and Threat Analysis, (6) Standards and Regulations,
operations, ranging from flight scheduling, air traffic control,
(7) Cybersecurity Framework, and (8) Case Studies and Surveys.
baggage handling, and security systems [1], [5], [8].
Table 2 presents the number of publications in each category
This diversity broadens the attack surface, introducing potential
and highlights specific airport security risks where applicable.
vulnerabilities and inadequate security practices from vendor
Critical Infrastructure. This category focuses on the critical
[17], [19], [20] - [22], [25], [36], [37].
infrastructures of airports, such as communication protocols,
Phishing. Although no new incidents have been disclosed
Air Traffic Management (ATM), and surveillance technologies
recently, phishing remains a significant threat with airport
[41] - [47]. These studies analyze vulnerabilities and mitigations,
employees and customers vulnerable to scams [38]. During
with examples including man-in-the-middle attacks between
a recent global outage linked to CrowdStrike [39], opportunistic
aircraft and ground control [42], the lack of encryption in
hackers exploited the situation by sending fake information to
the Automatic Dependent Surveillance-Broadcast (ADS-B)
scam IT personnel [40].
[43], [45], and the security concerns related to digitization of the Traffic Collision Avoidance System (TCAS) [44].
3. Research Methodology
These findings underscore the need to address cybersecurity
This study synthesizes recent airport cybersecurity incidents,
risks in airports. To this end, we associate these publications
literature, insights from online sources, and an examination of
related to airport security risks as follows: (1) Insecure Network
various cybersecurity standards and policies. Our goal is to
Architecture, (2) Malware and Ransomware (3) Data Breach
identify and delineate the prevailing cybersecurity threats
and (4) DoS.
and risks, categorizing them in alignment with the MITRE
IoT, Smart Devices, and AI Technology. Research here
ATT&CK Matrix. By systematically mapping these risks to
addresses cybersecurity risks from IoT devices and AI
the Matrix, we provide a strategic approach for mitigating
technologies used in airport operations [1], [5], [8], [48] - [50].
cybersecurity risks and applying effective defense techniques
Consequently, we associate these publications with specific risks,
based on current best practices.
including: (1) Public-facing Access, (2) Insecure Network Architecture, (3) Internet-facing Applications and Services,
ปีี ที่่� 21 ฉบัับที่่� 2 กรกฎาคม - ธัันวาคม 2568
Vol. 21, No. 2, July - December 2025
วารสารเทคโนโลยีีสารสนเทศ มจพ. 49
Information Technology Journal KMUTNB
Research Paper: Safeguarding Skies: Airport Cybersecurity in the Digital Age
Table 1. Summary of Publicly Disclosed Notable Cybersecurity Incidents at Airports (2022-2024). Impact on Airport Services Attack Incident
Attack Incident Summary
Year
Attack Technique
Operational Disruption
Website or Application
Data Leakage
Threat Actor Type*
Seattle Airport [33]
The Port of Seattle confirmed that a ransomware attack caused significant outages at Seattle-Tacoma International Airport, affecting services like Wi-Fi, check-in kiosks, and passenger displays. The attack also resulted in some data being stolen and encrypted
2024
Ransomware
Pau-Pyre ́́ne ́́es Airport [34]
Pau-Pyre ́ ́ne ́ ́es Airport was hit by a ransomware attack from the MONTI group, which exfiltrated sensitive data and published it on the dark web.
2024
Ransomware
Croatia’s Split Airport [35]
Split Airport in Croatia experienced a ransomware attack that resulted in flight cancellations and delays. The incident has been linked to the Akira group, which is associated with the Russian-based Conti group.
2024
Ransomware
Los Angeles International Airport [36]
A hacker group, IntelBroker, exploited the airport's CRM system vulnerability, accessing a database with sensitive information (e.g., private plane owners' full names, emails, CPA numbers)
2024
Vulnerability Exploitation
Copenhagen Airport [31]
The airport website was taken offline. Passengers were advised to use their smartphones as an alternative to receive updates on their flights.
2024
DoS
Beirut International Airport [17]
Hackers displayed a message on screens at the airport threatening to bomb the airport.
2024
unknown
Long Beach Airport [18]
Part of Long Beach City system cyberattack. The website was taken offline.
2023
Ransomware
•
2
Cairo International Airport [23]
The airport website and mobile application were taken down. Anonymous Collective hacker group took credit for the attack.
2023
DoS
•
3
Czech and Prague Airport [24]
The airport website was taken offline.
2023
DoS
•
3
Quere ́́taro Intercontinental Airport [19]
LockBit ransomware hacker group took credit for the attack, threatening to leak data. The airport claimed that stolen data was in the public domain.
2023
Ransomware
MontrealTrudeau International Airport [25]
Border checkpoint outages e.g., check-in kiosks and electronic gates caused significant delays. A hacker group, NoName057(16) claimed responsibility.
2023
DoS
Charles de Gaulle Airport [26]
The airport website was taken offline. Cybercriminal, Dark Storm, claimed responsibility.
2023
DoS
•
3
UK Airports [27]
The airport website was taken offline. UserSec hacker group claimed the responsibility.
2023
DoS
•
3
Kenya Airports Authority [20]
Data breach incident. Attackers released data including procurement plans, physical plans, site surveys, invoices and receipts.
2023
unknown
German Airports [28]
Several German airports’ websites were taken offline.
2023
DoS
•
3
US Major Airports [29]
Coordinated DoS attacks targeted several major US airports. A hacker group, Killnet claimed responsibility.
2022
DoS
•
3
Brazil Airports [37]
Rio de Janeiro airport’s electronic displays were hacked to show pornographic movies instead of ads and flight info.
2022
Vulnerability Exploitation
Italian Airports [30]
Coordinated DoS attacks targeted several Italian airports. A hacker group, Killnet claimed responsibility.
2022
DoS
Swissport at Zurich Airport [21]
Airport ground services and air cargo, Swissport, were hit with a ransomware attack causing Zurich Airport operation disruptions.
2022
Ransomware
•
•
2
•
2
•
2
•
•
unknown
•
3
•
•
2
3
•
•
2
unknown •
•
2
3 2
The sign ● indicates the impact on airport services from the attack. *The Threat Actor Type number delineates the category of cyber threat actors in Section 2.2
50 วารสารเทคโนโลยีีสารสนเทศ มจพ.
Information Technology Journal KMUTNB
ปีี ที่่� 21 ฉบัับที่่� 2 กรกฎาคม - ธัันวาคม 2568 Vol. 21, No. 2, July - December 2025
Research Paper: Safeguarding Skies: Airport Cybersecurity in the Digital Age
(4) Malware and Ransomware, (5) Data Breach, and
systematically manage risks and enhance resilience.
(6) DoS as these threats exploits internet connectivity used by
While many studies agree the necessity of these frameworks
IoT and smart devices. Furthermore, vulnerabilities in these
[1], [5], [8], [41], [55], [67], [68] for example, adopting
products can lead to supply chain attacks [51].
the National Institute of Standards and Technology's (NIST)
Supply Chain and Third Party. This category examines
Cybersecurity Framework to comply with ICAO standards [55],
cybersecurity vulnerabilities arising from supply chain and
only few recent publications [55], [67], [68] provide
third-party partnerships. For example, Hann (2020) emphasized
actionable details. Nevertheless these frameworks often lack
the complex socio-technical landscape of the ATM System [47],
comprehensive insights into adversary behavior, which are
emphasizing the need for attention to sectors critical to
essential for identifying and responding to threats throughout
airport operations, particularly in the context of digital cyber
an attack's lifecycle. Further details will be provided in Section 6.
warfare [51], as discussed.
Case Study and Survey. This category focuses on research
Cybersecurity Awareness. This category investigates
examining the cybersecurity posture of specific airports.
the effectiveness of cybersecurity awareness training within
Publications may present case studies based on geography
airport environments. While numerous studies have highlighted
[60], [62], [63], or specific events [69], [70] like the COVID-19
the significance of cybersecurity awareness training [1], [5], [8].
pandemic [70] to gather insights on cybersecurity practices
However, only one recent publication by Sabillon et al. (2023) [52]
and challenges.
has thoroughly examined this topic. We categorize these publications under the following risks: (1) Social Engineering, (2) Insider Threats, and (3) Data Breach, as these risks often arise from human [1], [5], [8], [52] - [54]. Risk and Threat Analysis. This research category conducts
5. Airport Security Risks This section provides detailed exploration of cybersecurity risks associated with attack vectors (Section 2.3) and those identified in our literature review (Section 4).
literature reviews to identify risks and threats affecting airports.
5.1 Public-facing Accesses
Studies provide insights into threats and recommend
BYOD. The practice of Bring-Your-Own-Device (BYOD)
improvements for threat detection and response [41], [43], [49],
commonly raises concern due to the exposure of organizations to
[55] - [64]. Numerous works study airport cybersecurity
vulnerabilities [71], [72]. However, in airport settings,
incidents [55] - [60], including threat actor typologies [58], [61]
passengers commonly use their personal devices. The diversity of
and associated risks and threats in relation to ICAO (International
connected devices in this context complicates device
Civil Aviation Organization) standards [55], which encompass
management [73], heightening the security risk when these
the entire spectrum of airport security risks.
devices connect to airport networks.
Standards and Regulations. Publications in this category
Public Access Services such as Wi-Fi access, check-in kiosks,
review existing cybersecurity standards and regulations
and charging stations enhance the passenger experience [6],
pertinent to the aviation sectors [63] - [66]. They study challenges
but they also increase risks by leaving users vulnerable to
and gaps in airport cybersecurity policies posed by rapid
cyberattacks [74] - [76], particularly if proper network
technological development and call for international
segmentation is not implemented.
cooperation and standardized policies, which currently remain insufficient [64].
Man-in-the-Middle (MITM) attacks are prevalent on public Wi-Fi, where cybercriminals eavesdrop using network
Cybersecurity Framework. This category investigates
snooping and sniffing tools to steal sensitive information
frameworks tailored for airports, focusing on models that
[75], [77]–[79]. Despite this, many critical websites continue to
NIST Cybersecurity Framework: https://www.nist.gov/cyberframework 1
ปีี ที่่� 21 ฉบัับที่่� 2 กรกฎาคม - ธัันวาคม 2568
Vol. 21, No. 2, July - December 2025
serve content over unencrypted connections [79] - [81].
วารสารเทคโนโลยีีสารสนเทศ มจพ. 51
Information Technology Journal KMUTNB
Research Paper: Safeguarding Skies: Airport Cybersecurity in the Digital Age
Table 2. Airport Cybersecurity Publications by Category and Associated Security Risks.
List of Publications
Number of Publications
[41] - [47]
9
Insecure Network Architecture Malware and Ransomware Data Breach DoS
[1], [5], [8], [48] - [50]
6
Public-facing Access Insecure Network Architecture Internet-facing Applications and Services Malware and Ransomware Data Breach Supply Chain and Third Party DoS
Supply Chain and Third Party
[47]
1
Supply Chain and Third Party
Cybersecurity Awareness
[52]
1
Social Engineering Insider Threats Data Breach
Risk and Threat Analysis
[41], [43], [49], [55] - [64]
13
Public-facing Access Insecure Network Architecture Internet-facing Applications and Services Social Engineering Malware and Ransomware Data Breach Supply Chain and Third Party Insider Threat DoS
Standard and Regulation
[63] - [66]
4
(inapplicable)
Cybersecurity Framework
[55], [67], [68]
3
(inapplicable)
Case Study and Survey
[60], [62], [63], [69], [70]
5
(inapplicable)
31
Public-facing Access Insecure Network Architecture Internet-facing Applications and Services Social Engineering Malware and Ransomware Data Breach Supply Chain and Third Party Insider Threat DoS
Publication Category Critical Infrastructure
IoT, Smart Devices and AI Technology
Total
Associated Security Risks (when applicable)
Malicious Hotspots. A malicious hotspot, also known as a "rogue access point" poses a significant threat to public Wi-Fi users. The attacker sets up a wireless access point with an identical SSID to deceive users, making users vulnerable to MITM or other network attacks [86] - [88]. 5.2 Insecure Network Architecture Figure 1. Basic Network Segmentation for Airport Security.
An insecure network architecture may allow attackers to
Malware from Untrusted Devices. In this attack,
gain access to internal systems and move laterally across
bad actors aim to inject malicious payload onto Wi-Fi users'
organization assets. Effective network segmentation is a key
devices [82], [83]. Adversaries may target vulnerabilities on
component, enabling administrators to manage network
popular devices, e.g., iOS [84]. Public charging stations also
interactions more securely by implementing security policies,
pose risks, known as "juice jacking", where attackers use
with varying levels of security and trust assigned to different
these stations to spread malware and extract data from
applications [89]. Figure 1 illustrates a basic example of network
smartphones [85].
segmentation applicable to an airport, where each segment
52 วารสารเทคโนโลยีีสารสนเทศ มจพ.
Information Technology Journal KMUTNB
ปีี ที่่� 21 ฉบัับที่่� 2 กรกฎาคม - ธัันวาคม 2568 Vol. 21, No. 2, July - December 2025
Research Paper: Safeguarding Skies: Airport Cybersecurity in the Digital Age
requires specific measures and is separated based on the different
phishing emails designed to deceive users into disclosing
entities and stakeholders involved, which can be described
financial information [61]. Some of these attacks predominantly
as follow:
target employees with privileged access to critical systems [8].
Public Wi-Fi. To prevent potential malicious activities
5.5 Malware and Ransomware
spreading to other airport entities such as CCTV systems [1]
Ransomware incidents often lead to airport operational
and malware incidents at Vienna Airport [90], it should be
disruptions and passenger experience [18], [19], [21], [33] - [35].
completely segregated from other airport networks.
Additionally, malware attacks may lead to data breaches,
IoT Devices. IoT devices often rely on vendor or
exposing sensitive information such as passenger records,
third-party-based solutions, making them vulnerable to
payment details, and employee credentials [31], [32].
third-party security risks (Section 5.7). Consequently, it is
Such breaches jeopardize privacy and can incur financial costs
recommended to isolate them from other networks, particularly
for airports, including remediations and regulatory fines.
critical networks.
5.6 Data Breach
Back Office is responsible for the administration, operations
Data breaches often results in the unauthorized access,
and logistics of the airport. Given the human-centric nature of
disclosure, or theft of sensitive information [19], [20], [33],
these operations, this network is prone to risks such as phishing,
[34], [36]. Additionally, breaches of sensitive operational
social engineering, and other human errors. This network
information can undermine airport operations and lead to
should be kept separated for added security.
security vulnerabilities [20]. In some cases, attackers may
Critical Infrastructures includes crucial assets for
exfiltrate data and demand ransom for its return or for
the airport operations. Access to this network should be
the decryption of compromised systems [32].
restricted from the public network, robust authentication and
5.7 Supply Chain and Third-Party
encryption measures must be implemented, as highlighted in
Security Vulnerabilities in systems can allow attackers to
several studies discussed in Section 4.
gain unauthorized access. These weaknesses may stem from
5.3 Internet-facing Applications and Services
known or unknown third-party software and hardware bugs, and
Security Vulnerabilities. Adversaries often exploit
misconfigurations [92]. Zero-day vulnerabilities pose particular
weaknesses in internet-facing applications such as airport
risks, as attacks can occur before developers issue patches.
websites, and mobile applications. These vulnerabilities can
Concerns about IoT and vendor solution vulnerabilities are
arise from software bugs, design flaws, or unpatched
amplified by the potential for threat actors to compromise
vulnerabilities, as discussed in Section 2.3 and Section 4.
not only the affected device but also other network assets [93].
Weak authentication practices in internet-facing
No Security Update Mechanism. Many solutions,
applications pose significant risks for airports, potentially
particularly IoT devices, may lack a security update mechanism,
leading to unauthorized access to critical systems. Additionally,
leaving them vulnerable even after patches have been
remote access for employees can further complicate security;
released [94].
if authentication credentials are weak, attackers may gain broader access to internal networks [91].
No Common Standards and Specifications. The lack of universally accepted standards for IoT device development
5.4 Social Engineering
leads to inconsistent implementations and design choices,
Phishing. Social engineering attacks exploit human
which negatively affect security. Users must manage multiple
vulnerabilities, with phishing being a significant concern. In 2013, over 75 U.S. airports reported incidents involving
ปีี ที่่� 21 ฉบัับที่่� 2 กรกฎาคม - ธัันวาคม 2568
Vol. 21, No. 2, July - December 2025
technologies to effectively support these devices [5]. Supply Chain Compromise involves manipulating products
วารสารเทคโนโลยีีสารสนเทศ มจพ. 53
Information Technology Journal KMUTNB
Research Paper: Safeguarding Skies: Airport Cybersecurity in the Digital Age
before they reaches consumer, creating vulnerabilities in
arising from these identified risks.
critical systems. For example, compromised chips or drivers
6.1. MITRE Matrix: TTPs
in smart devices at airports can expose systems to attack [95].
The MITRE Matrix categorizes attacker tactics and techniques.
High-profile incidents, such as the SolarWinds hack, affected
Each tactic represents a high-level goal, while the techniques
over 18,000 networks globally [96]. Additionally, a recent
describe the specific methods employed to achieve that goal,
incident in Lebanon further illustrates the dangers, where
both indexed for easy reference. Each technique includes
devices were reportedly manipulated for digital warfare [51].
(1) procedures based on real-world incidents, (2) mitigations
No Physical Hardening. IoT devices are often deployed in
with actionable defense recommendations such as configurations
various locations throughout the airport, making them
and tools, and (3) detection strategies and recommendations
vulnerable to tampering during unattended operations.
for identifying the attacks. We believe that this comprehensive
Physical access can result in theft and unauthorized access to
information enables airport security personnel to effectively
internal circuits and overwriting changes [1].
implement strategies to mitigate identified risks.
5.8 Insider Threat
6.2 Airport Security Risks with the MITRE Matrix
An insider threat is a security risk posed by individuals
The MITRE Matrix is a valuable tool for identifying and
who misuse their access or privileged accounts. A malicious
mapping airport security risks related to potential attacks.
insider, often referred to as a "Turncloak," intentionally abuses
Given the complexity of vulnerabilities, some risks may align
legitimate access to steal sensitive information or manipulate
with multiple MITRE techniques. This paper focuses on
critical aviation systems. Mitigating this threat involves
two key tactics: Initial Access (TA001) and Impact (TA0040).
adhering to information security management standards and
Initial Access is fundamental as it represents the first step for
guidelines [97].
adversaries to gain entry into protected systems. The Impact
5.9 Denial-of-Service
tactic, particularly T1498 (Network Denial of Service), is
As outlined in Section 2, DoS attacks on airport websites are
emphasized due to its prevalence due to its frequency in recent
significant threats to the aviation sector, with recent treads
incidents discussed in Section 2.3.
showing demands ransom payments to stop these attacks, aided by the anonymity of cryptocurrencies [32].
Table 3 provides an overview of categorized airport security risks and their associated MITRE techniques, listing all ten Initial Access techniques and one Impact technique
6. Airport Security Risks and MITRE ATT&CK Matrix This section provides a comprehensive analysis of
(retrieved September 2024). Each technique is identified and referenced by an ID (e.g., T1189, T1190).
the security risks faced by airports, categorizing these risks
6.3 MITRE Initial Access Techniques (TA0001)
in alignment with the MITRE ATT&CK Matrix for Enterprise
Initial Access is a critical phase in the cyber kill chain,
(or MITRE Matrix) [98]. This widely adopted cybersecurity
representing the methods adversaries use to gain entry into
knowledge base outlines the tactics, techniques and procedures
target systems. Below are the relevant techniques from
(TTPs) utilized globally for threat analysis and security defenses.
the MITRE Matrix associated with Initial Access and
Notably, this paper is the first to propose applying the MITRE
the corresponding airport security risks:
Matrix to bolster the cybersecurity posture of airports.
Public-facing Access (T1659, T1190, T1200): Techniques
We correlate all identified airport security risks—derived
such as Content Injection (T1659) allow attackers to insert
from cybersecurity incidents and a systematic literature
malicious content into network traffic, often through public Wi-Fi.
review—with MITRE techniques to mitigate cyberattacks
Exploiting vulnerabilities in public-facing applications (T1190),
MITRE Matrix Initial Access Tactic: https://attack.mitre.org/tactics/TA0001/
3
2
54 วารสารเทคโนโลยีีสารสนเทศ มจพ.
Information Technology Journal KMUTNB
MITRE Matrix Impact Tactic: https://attack.mitre.org/tactics/TA0040/
ปีี ที่่� 21 ฉบัับที่่� 2 กรกฎาคม - ธัันวาคม 2568 Vol. 21, No. 2, July - December 2025
Research Paper: Safeguarding Skies: Airport Cybersecurity in the Digital Age
Table 3. Summary of Airport Security Risks Linked to MITRE Matrix Tactics and Techniques. Impact: TA0040
Initial Access: TA0001
Airport Security Risk T1659
T1189
T1190
T1133
1. Public-facing Accesses
•
•
2. Insecure Network Architecture
•
•
•
•
•
3. Internet-facing Applications and Services
T1200
T1566
T1091
•
•
T1195
T1199
T1078
•
4. Social Engineering Attacks
•
•
5. Malware and Ransomware
•
•
•
•
•
•
•
•
•
•
6. Data Breach
•
•
•
•
•
•
•
•
•
•
•
•
•
•
7. Supply Chain and Third Party
T1498
8. Insider Threats
•
•
•
9. DoS
• •
The sign ● indicates that the airport security risk shown can be categorized according to the specific MITRE Matrix technique.
Associated MITRE Initial Access Tactic (TA0001)
ID
Technique
T1659 T1189 T1190 T1133 T1200 T1566 T1091 T1195 T1199 T1078
Content Injection Drive-by Compromise Exploit Public-Facing Application External Remote Services Hardware Additions Phishing Replication Through Removable Media Supply Chain Compromised Trusted Relationship Valid Accounts Associated MITRE Impact Tactic (TA0040)
ID
Technique
T1498
Network Denial of Service
Internet-facing Applications and Services (T1190, T1133): The presence of internet-facing applications and services exposes airports to significant cybersecurity risks via techniques such as Exploiting Public-facing Applications (T1190) and External Remote Services (T1133). Attackers can target vulnerabilities within publicly accessible systems—like online booking websites and service APIs—to gain unauthorized access to sensitive assets. Insecure remote services can also create entry points for attackers, allowing them to gain unauthorized access to internal systems through airport VPNs [100].
such as kiosks and charging stations, can provide unauthorized
Social Engineering (T1659, T1189, T1566, T1091, T1078):
access due to unpatched vulnerabilities or misconfigurations.
Techniques such as Content Injection (T1659), Drive-by
This may be coupled with Hardware Additions (T1200),
Compromise (T1189), and Phishing (T1566) are utilized to
where attackers exploit exposed ports to introduce unauthorized
manipulate victims. The use of insecure removable media
devices [99].
(T1091) may allow untrusted devices to introduce malware to
Insecure Network Architecture (T1659, T1190, T1133):
critical systems [101]. Technique like Valid Accounts
Techniques such as Content Injection (T1659) and Exploiting
(T1078) may enable attackers to gain access via stolen account.
Public-facing Applications (T1190) become more dangerous in
Malware, Ransomware and Data Breach (T1659,
poorly secured environments, allowing attackers to gain initial
T1189, T1190, T1133, T1200, T1566, T1091, T1195,
access and subsequently move laterally. Additionally, External
T1199, T1078): Malware, ransomware, and data breaches
Remote Services (T1133) may compromise internal network by
exploit various techniques within airport systems. Initial Access
enabling unauthorized access through insecure remote connections.
tactics, such as Content Injection (T1659) and Exploiting
ปีี ที่่� 21 ฉบัับที่่� 2 กรกฎาคม - ธัันวาคม 2568
Vol. 21, No. 2, July - December 2025
วารสารเทคโนโลยีีสารสนเทศ มจพ. 55
Information Technology Journal KMUTNB
Research Paper: Safeguarding Skies: Airport Cybersecurity in the Digital Age
Public-facing Applications (T1190) enable attackers to
7.1 Cybersecurity Frameworks and Requirements
infiltrate via public interfaces. Techniques like Drive-by
Numerous studies emphasize the important of adopting
Compromise (T1189), Phishing (T1566), and the use of
cybersecurity frameworks to enhance airport security [1], [5], [8],
insecure removable media (T1091) increase the risk of malware
[41], [55], [67], [68]. Frameworks, such as NIST Cybersecurity
and ransomware, ultimately leading to data breaches.
Framework, can help identify weaknesses and facilitate
External Remote Services (T1133) and Valid Accounts (T1078)
development of security objectives. The Civil Air Navigation
allow attackers to leverage stolen credentials to penetrate
Services Organization (CANSO) has proposed guidelines to
into the networks, facilitating ransomware and data theft.
elevate security levels through these frameworks [102], and
Risks from Supply Chain Compromise (T1195) and Trusted
several airports, including Airports of Thailand, have already
Relationship (T1199) may introduce vulnerabilities into
implemented such policies [103].
overall security.
Recently, the TSA issued new cybersecurity requirements,
Supply Chain and Third Party (T1195, T1199): With
mandating all U.S. airports and aircraft operators to develop
multiple party involved, techniques such as Supply Chain
cybersecurity policies [104], [105]. Additionally, ICAO has
Compromise (T1195) and Trusted Relationship (T1199)
created Standards and Recommended Practices [106], [107]
presents significant threat to airports, allowing attackers to
that urge airports to implement cybersecurity risk management
exploit vulnerabilities without raising immediate suspicion.
frameworks and collaborate to advance ICAO's cybersecurity
Insider Threat (T1091, T1199, T1078): Techniques
framework.
such as Insecure Removable Media (T1091) can enable
7.2 Zero Trust Architecture
employees to introduce malware into the system.
Zero Trust is a modern cybersecurity framework that
Exploitation of Trusted Relationships (T1199) may allow
prioritizes verifying and protecting all entities based on
insiders to manipulate external connections, leading to
the principle of least privilege. It involves capturing and
unauthorized sharing of sensitive information. Additionally,
analyzing logs for effective threat response, acknowledging
Valid Accounts (T1078) could allow insiders to misuse their
that internal threats may stem from untrusted devices and
credentials.
personnel. The following discussion highlights the benefits
6.4 MITRE Impact (TA0040) for Denial-of-Service
of implementing Zero Trust architecture in airport security.
Denial-of-Service (T1498): According to the MITRE
Visibility for Subsystems. The initial phase of
framework, DoS attacks fall under the Impact tactic, specifically
an integrated Zero Trust architecture involves identifying
technique ID T1498. This can be executed through methods
organizational assets, their value, stakeholders, and connectivity.
such as direct network floods (T1498.001) or reflection
This foundational step prioritizes Zero Trust security policies,
amplification (T1498.002).
including secure access, the principle of least privilege, and enhanced visibility into subsystems.
7. Modern Defenses for Airport Security
Network Segmentation. Network segmentation is
In this section, we outline modern security defense strategies
a foundational element of the Zero Trust architecture, allowing
and best practices specifically designed for airport.
network administrators to enforce the principle of least privilege.
The key focus areas include the adoption of Cybersecurity
For instance, the IoT network is isolated from other segments to
Frameworks and the implementation of Zero Trust Architecture,
prevent unauthorized parties from exploiting IoT vulnerabilities
along with additional defenses addressing the identified risks
and mitigate the risk of lateral movement within the airport's
in previous sections.
infrastructure.
56 วารสารเทคโนโลยีีสารสนเทศ มจพ.
Information Technology Journal KMUTNB
ปีี ที่่� 21 ฉบัับที่่� 2 กรกฎาคม - ธัันวาคม 2568 Vol. 21, No. 2, July - December 2025
Research Paper: Safeguarding Skies: Airport Cybersecurity in the Digital Age
Demilitarized Zone. Internet-based services are prime
encompass regular off-site data backups. These backups
targets for cyberattacks, making it essential to configure
must be secured against common threats, such as ransomware
a separate network segment called a "Demilitarized Zone" (DMZ).
that seeks to compromise backup files (T1486) [109].
The DMZ acts as a controlled gateway between the internal
Routine testing of backup restoration procedures is crucial to
network and the internet, enforcing strict connectivity rules
ensure their usability in the event of an incident.
through firewalls and packet filtering.
Data Breach Prevention involves proactive monitoring
The External Policy Enforcement Point (PEP) in Figure 2
of data for irregular patterns—such as unexpected changes in
filters malicious internet traffic, while the Internal PEP manages
data size, unusual timestamps, or unauthorized access
the traffic between DMZ servers and the internal network.
attempts—is essential for early detection of potential breaches.
This layered security approach ensures that external services
Strong authentication and encryption for data access further
remain isolated from internal systems.
safeguard sensitive information from unauthorized users
7.3 Security Awareness Training. The aviation sector may soon face regulatory mandates requiring security
and ensure compliance with relevant regulatory data security and privacy requirements.
awareness training for employees [4], [7]. To effectively
7.5 Supply Chain and Third Party Risk Management
implement such programs, organizations actively engage in
Due Diligence in Supply Chain Management.
the development process, providing continuous feedback to
Any third-party solutions integrated into airport systems
enhance the training effectiveness.
must be treated as part of the airport's threat landscape. A rigorous selection process should assess adaptability, security features, secure update mechanisms, and support systems to effectively manage security liabilities and reduce the risk of unforeseen incidents. Physical Access Restrictions and Tamper Proofing. IoT devices deployed throughout airports are susceptible to
Figure 2. DMZ subnet that separates an enterprise internal network from other untrusted networks e.g., the Internet.
physical access attacks, where criminals may steal them for unauthorized entry. To mitigate this risk, various tamper-proof techniques can be applied [110], [111]. For instance, devices
7.4 Malware, Ransomware and Data Breach
can be housed in secure or tamper-resistant cases and
In addition to previously discussed security measures,
disabling or factory resetting.
airports should implement targeted strategies to detect malware
7.6 Insider Threat Mitigation
and ransomware. The following mitigation strategies can
Mitigating insider threats is challenging, as they often
strengthen an airport's cybersecurity posture:
bypass traditional security measures. Prevention relies on
Endpoint Detection and Response (EDR). To bolster
the principle of least privilege, restricting user access to
cybersecurity, airports should implement advanced anomaly
essential functions, along with monitoring for anomalous
detection and monitoring to swiftly identify unusual patterns
behaviors. Implementing a Zero Trust Architecture strengthens
indicative of ransomware. EDR solutions provide real-time
security by requiring identity verification for every access
analysis of host activities, enabling rapid detection of malicious
request and ensuring all access is logged and analyzed.
behaviors [108].
7.7 Denial-of-Service Mitigation
Data Backup and Disaster Recovery. It is imperative to
Cloud or Hybrid DoS Scrubbing Platforms enhance
implement comprehensive IT disaster recovery plans that
security by redirecting traffic through specialized infrastructure
ปีี ที่่� 21 ฉบัับที่่� 2 กรกฎาคม - ธัันวาคม 2568
Vol. 21, No. 2, July - December 2025
วารสารเทคโนโลยีีสารสนเทศ มจพ. 57
Information Technology Journal KMUTNB
Research Paper: Safeguarding Skies: Airport Cybersecurity in the Digital Age
that filters out malicious traffic before it reaches the airport's
Generative AI, focusing on their effectiveness in enhancing
network [112], [113]. Incorporating redundancy and failover
airport operations while mitigating potential vulnerabilities.
mechanisms is also essential, as it improves resilience and
While existing studies have started to address these gaps,
minimizes downtime, ensuring essential services remain
ongoing research is essential to keep up with emerging
operational during an attack.
threats and solutions.
7.8 Collaborative Threat Intelligence Sharing Numerous studies underscore the importance of information
9. Conclusion
sharing within the industry [5], [61], [64], [114]. A real-world
This paper explores the critical area of airport cybersecurity,
example demonstrates the effectiveness: during a spear phishing
highlighting the seriousness of emerging threats in this domain.
campaign targeting airport executives, emails containing
Through insights gained from recent real-world incidents
malware were detected. Through collaborative efforts,
and a systematic literature review, we conducted a comprehensive
the attack was neutralized across the sector [115]. By adopting
analysis and categorized major cybersecurity risks confronting
a multi-faceted approach, including collaborative threat
airports, aligned with the MITRE ATT&CK Matrix, providing
intelligence sharing, airports can enhance their defenses
a valuable framework for exploring practical defenses and
against evolving cyber threats.
best practices articulated in the MITRE knowledge base. In conclusion, we advocate for the adoption of modern
8. Challenges and Future Research Directions
security policies, including robust Cybersecurity Frameworks
While a range of defenses have been detailed, significant
and Zero Trust Architecture, alongside critical security measures.
challenges remain that must be addressed in order to further
This study aims to enhance the aviation industry's understanding
enhance airport cybersecurity
of the current threat landscape and provide a foundation
Evolving Threat Landscape. Cyber threats are continuously
for enhancing cybersecurity defense and resilience.
evolving and becoming more sophisticated, and diversified. This necessitates ongoing research and airport adaptability to
10. References
counter new attack vectors.
[1]
G. Lykou, A. Anagnostopoulou, and D. Gritzalis.
Resource Constraints. Smaller airports often face significant
"Smart Airport Cybersecurity: Threat Mitigation
resource limitations e.g., budget and personnel, hindering
and Cyber Resilience Controls." Sensors, Vol. 19,
the implementation of cybersecurity measures.
No. 1, 2019.
Integration of Legacy Systems. Integrating modern
[2]
EUROCONTROL, Aviation under Attack from
security measures with outdated systems presents significant
a Wave of Cybercrime. Available Online at https://
challenges and often requires substantial investment.
www.eurocontrol.int/publication/eurocontrol-
Future Research Directions. Our literature review reveals
think-paper-12-aviation-under-attack-wave-cyber
a pressing need for further research in key areas: (1) Supply Chain
crime, accessed on 1 February 2024.
and Third-Party Risks, (2) Cybersecurity Awareness, and
[3]
Business Insurance, US to add cybersecurityrequirements
(3) Development of Airport-Specific Cybersecurity Frameworks.
for critical aviation systems. Available Online at
The limited publications in these domains highlight the unique
https://www.businessinsurance.com/article/20221012/
challenges airports face.
NEWS06/912353045/US-to-add-cybersecurity-re
Additionally, future research should investigate the integration
quirements-for-critical-aviation-systems, accessed on
of advanced technologies like Machine Learning, AI, and
1 February 2024.
58 วารสารเทคโนโลยีีสารสนเทศ มจพ.
Information Technology Journal KMUTNB
ปีี ที่่� 21 ฉบัับที่่� 2 กรกฎาคม - ธัันวาคม 2568 Vol. 21, No. 2, July - December 2025
Research Paper: Safeguarding Skies: Airport Cybersecurity in the Digital Age
[4]
IATA, Compilation of Cyber Security Regulations,
https://www.bloomberg.com/news/articles/2021-06-04/
Standards, and Guidance Applicable to Civil Aviation
hackers-breached-colonial-pipeline-using-com
Edition 3.0. Available Online at https://www.iata.org/
promised-password, accessed on 1 February 2024.
c o n t e n t a s s e t s / 4 c 5 1 b 0 0 f b 2 5 e 4 b 6 0 b
[13]
CNN, Ransomware attack hits New Jersey county.
38376a935e278b/compilation-of-cyber-regulations-
Available Online at https://www.cnn.com/2022/05/26/
standards-and-guidance3.0.pdf, accessed on
politics/new-jersey-somerset-county-ransomware-
1 February 2024.
attack, accessed on 1August 2023.
[5]
N. Koroniotis, N. Moustafa, F. Schiliro, P. Gauravaram,
[14]
Threatpost, N.J.'s Largest Hospital System Pays Up
and H. Janicke. "A Holistic Review of Cybersecurity
in Ransomware Attack. Available Online at https://
and Reliability Perspectives in Smart Airports."
threatpost.com/ransomware-attack-new-jersey,
IEEE Access, Vol. 8, pp. 209802-209834, 2020.
accessed on 1 February 2024.
[6]
A. Fattah, H. Lock, W. Buller, and S. Kirby. Smart
[15]
Mandiant, Advanced Persistent Threats (APTs) --
Airports: Transforming Passenger Experience to
Threat Actors & Groups. Available Online at
Thrive in the New Economy. Available Online at
https://www.mandiant. com/resources/insights/apt-
https://www.cisco.com/c/dam/en_us/about/ac79/
groupsm, accessed on 1 June 2023.
docs/pov/Passenger_Exp_POV_0720aFINAL.pdf,
[16]
ZDNET, Russian state hackers behind San Francisco
accessed on 1 February 2024.
Airport Hack. Available Online at https://www.zdnet.
[7]
TSA, 20 years after 9/11: The state of the transportation
com/article/russian-state-hackers-behind-san-fran
security administration. Available Online at https://
cisco-airport-hack/, accessed on 1 February 2024.
shorturl.at/1lsGo, accessed on 1 February 2024.
[17]
Security Affairs, A Cyber Attack Hit The Beirut
[8]
G. Lykou, A. Anagnostopoulou, and D. Gritzalis.
International Airport. Available Online at https://
"Implementing Cyber Security Measures in Airports to
securityaffairs.com/157079/hacking/cyber-attack-
Improve Cyber Resilience." Proceedings of the 2018
hit-beirut-international-airport.html, accessed on
Global Internet of Things Summit, pp. 1-6, 2018.
1 February 2024.
[9]
J. H. Tan and T. Masood. "Adoption of Industry 4.0
[18]
Homeland Security Today, Long Beach Airport’s
Technologies in Airports - A Systematic Literature
Website Taken Down By Cyber Attack. Available
Review." ArXiv, pp. 1-25, 2021.
Online at https://www.hstoday.us/subject-matter-areas/
[10]
M. Javaid, A. Haleem, R. P. Singh, R. Suman, and
transportation/long-beach-airports-website-taken-
E. S. Gonzalez. "Understanding the Adoption of
down-by-cyber-attack/, accessed on 1 June 2023.
Industry 4.0 Technologies in Improving Environmental
[19]
The Record, Major Mexican airport confirms experts
Sustainability." Sustainable Operations and Computers,
are working to address cyberattack. Available Online at
Vol. 3, pp. 203 - 217, 2022.
https://therecord.media/queretaro-international-airport-
[11]
K. Gopalakrishnan, M. Govindarasu, D. Jacobson,
mexico-cyberattack, accessed on 1 February 2024.
and B. M. Phares. "Cyber Security for Airports."
[20]
NTV, KAA confirms data breach, says no sensitive
International Journal for Traffic and Transport
data leaked. Available Online at https://ntvkenya.
Engineering (IJTTE), Vol. 3, No. 4, pp. 365-376, 2013.
co.ke/news/kaa-confirms-data-breach-says-no-
[12]
Bloomberg, Colonial Pipeline Cyber Attack: Hackers
sensitive-data-leaked/, accessed on 1 May 2023.
Used Compromised Password. Available Online at
[21]
Airport Technology, Ransomware attack on Swissport
ปีี ที่่� 21 ฉบัับที่่� 2 กรกฎาคม - ธัันวาคม 2568
Vol. 21, No. 2, July - December 2025
วารสารเทคโนโลยีีสารสนเทศ มจพ. 59
Information Technology Journal KMUTNB
Research Paper: Safeguarding Skies: Airport Cybersecurity in the Digital Age
causes delay at Zurich Airport. Available Online at
knock US airport websites offline. Available Online at
https://www.airport-technology.com/news/ransomware-
https://apnews.com/article/technology-business-
attack-swissport-zurich-airport/, accessed on
atlanta-680cf93f7eb0300127448c35299ad66e,
1 February 2024.
accessed on 1 February 2024.
[22]
Security Affairs, A Cyber Attack Hit The Beirut
[30]
Euractiv, Italy target of major Russia-linked cyberattack,
International Airport. Available Online at https://
again. Available Online at https://shorturl.at/Kvn9C,
securityaffairs.com/157079/hacking/cyber-attack-
accessed on 1 February 2024.
hit-beirut-international-airport.html, accessed on
[31]
CyberMaterial, Cyberattack Hit Copenhagen Airport.
1 February 2024.
Available Online at https://cybermaterial.com/
[23]
The Cyber Express, DDoS Cyberattack Hits Cairo
cyberattack-hit-copenhagen-airport/, accessed on
International Airport: Anonymous Collective Claims
1 February 2024.
Responsibility. Available Online at https://thecyberexpress.
[32]
The Wall Street Journal, Why Hackers Use Bitcoin
com/cairo-international-airport-cyberattack, accessed on
and Why It Is So Difficult to Trace. Available Online
1 February 2024.
at https://www.wsj.com/articles/why-hackers-use-
[24]
Czech Police, Interior Ministry, Airport Websites
bitcoin-and-why-it-is-so-difficult-to-trace-
Come Under Cyber Attack. Available Online at
11594931595, accessed on 1 February 2024.
https://brnodaily.com/2023/10/24/news/czech-
[33]
SecurityWeek, Data Stolen in Ransomware Attack That
police-interior-ministry-airport-websites-come-under-
Hit Seattle Airport. Available Online at https://www.
cyber-attack/, accessed on 1 February 2024.
securityweek.com/data-stolen-in-ransomware-attack-
[25]
The Record, Canada blames border checkpoint
that-hit-seattle-airport, accessed on 1 February 2024.
outages on cyberattack. Available Online at https://
[34]
Halcyon Tech, Monti Ransomware Attack on Ae ́ŕ oport
therecord.media/canada-border-checkpoint-outages-
de Pau. Available Online at https://ransomwareattacks.
ddos-attack-russia, accessed on 1 May 2023.
halcyon.ai/attacks/monti-ransomware-attack-on-
[26]
Tech Monitor, Charles de Gaulle Airport website
aeroport-de-pau, accessed on 1 February 2024.
offline after suspected '#OpFrance' DDoS cyberattack.
[35]
BARRON'S, Cyberattack Hits Croatia’s Split Airport.
Available Online at https://techmonitor.ai/technology/
Available Online at https://www.barrons.com/
cybersecurity/opfrance-cyberattack-charles-de-gaulle-
news/cyberattack-hits-croatia-s-split-airport-
airport, accessed on 1 June 2023.
dac3d776, accessed on 1 February 2024.
[27]
Mirror, UK airports targeted by coordinated Russia
[36]
HACKREAD, Hackers Leak 2.5M Private Plane
cyberattack groups. Available Online at https://
Owners' Data Linked to LA Intl. Airport Breach.
www.mirror.co.uk/travel/news/uk-airports-targeted-
Available Online at https://hackread.com/hackers-leak-
coordinated-russia-30504938, accessed on
private-plane-owners-data-la-airport-breach/,
1 February 2024.
accessed on 1 August 2024.
[28]
Information Week, The DDoS Attack on German
[37]
AP, Hacked Brazil Airport Screens Show Porn
Airport Websites and What IT Leaders Can Learn.
to Travelers. Available Online at https://apnews.
Available Online at https://shorturl.at/7ACXL,
com/article/entertainment-caribbean-brazil-
accessed on 1 February 2024.
c0842e915c403c41830 6433cdfc406a6, accessed on
[29]
The Associated Press, Denial-of-service attacks
1 February 2024.
60 วารสารเทคโนโลยีีสารสนเทศ มจพ.
Information Technology Journal KMUTNB
ปีี ที่่� 21 ฉบัับที่่� 2 กรกฎาคม - ธัันวาคม 2568 Vol. 21, No. 2, July - December 2025
Research Paper: Safeguarding Skies: Airport Cybersecurity in the Digital Age
[38]
KTSM.com, FBI warns cyber criminals are spoofing
2021 IEEE 11th Annual Computing and Communication
airport websites and Wi-Fi. Available Online at
Workshop and Conference (CCWC), NV, USA,
https://shorturl.at/vJRE7, accessed on 1 February 2024.
pp. 565-571, 2021.
[39]
The New York Times, Stranded in the CrowdStrike
[47]
J. Haan. "Specific Air Traffic Management Cybersecurity
Meltdown: 'No Hotel, No Food, No Assistance'.
Challenges: Architecture and Supply Chain."
Available Online at https://www.nytimes.com/
ICSEW'20: Proceedings of the IEEE/ACM 42nd
2024/09/13/travel/crowdstrike-outage-delta-airlines.
html, accessed on 1 February 2024.
Workshops, New York, NY, USA, pp. 245-249, 2020.
[40]
BCC, Scam warning as fake emails and websites
[48]
C. Aranzazu-Suescun, L. F. Zapata-Rivera,
target users after outage. BBC. Available Online at
O. G.-M. Saenz, and J. M. Christensen. "Securing
https://www.bbc.com/news/articles/cq5xy12pynyo,
IoT Surveillance Airport Infrastructure."
accessed on 1 February 2024.
Proceedings of the 2024 International Conference
[41]
G. Dave, G. Choudhary, V. Sihag, I. You, and
K.-K. R. Choo. "Cyber Security Challenges in Aviation
Networking, Harrisonburg, VA, USA, pp. 1-7, 2024.
Communication, Navigation, and Surveillance."
[49]
E. Pik. "Airport Security: The Impact of AI on Safety,
Computers & Security, Vol. 112, 2022.
Efficiency, and the Passenger Experience."
[42]
E. Andreev and D. Dimitrov. "Analysis of Cyber
Journal of Transportation Security, Vol. 17, No. 1,
Vulnerabilities in Civil Aviation and Recommendations
December, 2024.
for Their Mitigation." Aeronautical Research and
[50]
D. Shevchuk and I. Steniakin. "A Holistic Approach to
Development, Vol. 1, pp. 90-99, 2022.
Ensuring Safety and Cybersecurity in the Use of
[43]
A. Elmarady and K. Rahouma. "Studying Cybersecurity
Intelligent Technologies in Air Transport."
in Civil Aviation, including Developing and Applying
Electronics and Control Systems, Vol. 1, No. 75,
Aviation Cybersecurity Risk Assessment." IEEE Access,
pp. 97-101, 2023.
Vol. 4, 2016.
[51]
The Wall Street Journal, Pager Attacks in Lebanon
[44]
M. L. Salgado and M. S. de Sousa. "Cybersecurity
'Weaponize' Supply Chains. Available Online at
in Aviation: The STPASEC Method Applied to
https://www.wsj.com/articles/pager-attacks-in-lebanon-
the TCAS Security." 2021 10 th Latin-American
weaponize-supply-chains-60722390, accessed on
Symposium on Dependable Computing (LADC),
1 February 2024.
Florianópolis, Brazil, pp. 1-10, 2021.
[52]
R. Sabillon and J.R.B. Higuera. "The Importance of
[45]
S. Khandker, H. Turtiainen, A. Costin, and T. Hämäläinen.
Cybersecurity Awareness Training in the Aviation
"Cybersecurity Attacks on Software Logic and Error
Industry for Early Detection of Cyberthreats and
Handling within ADS-B Implementations: Systematic
Vulnerabilities." International Conference on Human-
Testing of Resilience and Countermeasures." IEEE
Computer Interaction, pp. 461-479, 2023.
Transactions on Aerospace and Electronic Systems,
[53]
S. Chockalingam, E. Nystad, and C. Esnoul.
Vol. 58, No. 4, pp. 2702-2719, 2022.
"Capability Maturity Models for Targeted Cyber
[46]
A. A. Alsulami and S. Zein-Sabatto. "Resilient Cyber-
Security Training." Proceedings of the International
security Approach for Aviation Cyber-physical
Conference on Human-Computer Interaction,
Systems Protection against Sensor Spoofing Attacks."
pp. 576-590, 2023.
ปีี ที่่� 21 ฉบัับที่่� 2 กรกฎาคม - ธัันวาคม 2568
Vol. 21, No. 2, July - December 2025
International Conference on Software Engineering
on Smart Applications, Communications and
วารสารเทคโนโลยีีสารสนเทศ มจพ. 61
Information Technology Journal KMUTNB
Research Paper: Safeguarding Skies: Airport Cybersecurity in the Digital Age
[54]
The Hacker News, Why Human Error is #1 Cyber
Security Threat to Businesses in 2021. Available
Journal, Vol. 4, No. 3, pp. 267-291, 2021.
Online at https://thehackernews.com/2021/02/
[63]
M. Karpiuk and M. Kelemen. "Cybersecurity in
why-human-error-is-1-cyber-security.html, accessed on
Civil Aviation in Poland and Slovakia." Cybersecurity
1 February 2024.
and Law, Vol. 8, No. 2, pp. 70-83, 2022.
[55]
P. Stastny and A. M. Stoica. "Protecting Aviation
[64]
C. Nobles, D. Burrell, and T. Waller. "The Need for
Safety Against Cybersecurity Threats." IOP Conference
a Global Aviation Cybersecurity Defense Policy"
Series: Materials Science and Engineering, Vol. 1226,
Land Forces Academy Review, Vol. 27, No. 1,
No. 1, pp. 12-25, 2022.
pp. 19-26, March 2022.
[56]
H. Saada, R. Orizio, and S. Sebastio. "Modeling
[65]
V. Filinovych and Z. Hu. "Aviation and the Cybersecurity
and Conducting Security Risk Assessment of Smart
Threats." Proceedings of the International Conference
Airport Infrastructures with SECRAM." Proceedings of
on Business, Accounting, Management, Banking,
the 7th International Conference on Networking,
Economic Security and Legal Regulation Research
Intelligent Systems and Security, No. 59, pp. 1-7, 2024.
(BAMBEL 2021), pp. 120-126, 2021.
[57]
T. Jeeradist. "Flight Delays and Cancellations Due to
[66]
M. Klenka. "Aviation Cyber Security: Legal Aspects
Airport Technology Network Disruptions Worldwide."
of Cyber Threats." Journal of Transportation Security,
KBU Journal of Aviation Management: KBUJAM,
Vol. 14, No. 3, pp. 177-195, December, 2021.
Vol. 2, No. 1, pp. 51-60, 2024.
[67]
S. Adhikari and S. Mirchandani. "Integrating Risk
[58]
L. Florido-Benítez. "The Types of Hackers and
Assessment Modeling with Aviation Cybersecurity
Cyberattacks in the Aviation Industry." Journal of
Framework." AIAA AVIATION 2020 FORUM,
Transportation Security, Vol. 17, No. 13, 2024.
pp. 29-32, 2020.
[59]
H. Su and W. Pan. "Using Digital Twins to Integrate
[68]
S. Adhikari. "An Analysis of AIAA Aviation
Cyber Security with Physical Security at Smart
Cybersecurity Framework in Relation to NIST,
Airports." Interdisciplinary Journal of Engineering
COBIT and DHS Frameworks." AIAA AVIATION
and Environmental Sciences, Vol. 10, No. 1,
2020 FORUM, pp. 2930, 2020.
pp. 38-45, January-March, 2023.
[69]
B. Kotkova. "Information Systems and Technologies
[60]
S. Samuri, M.F.A. Khir, Z.M. Amin, and M. F. N.
for the Safe Operation of Airports." Proceedings of
Mohammad. "Cybersecurity Maturity Framework
the 26th International Conference on Circuits, Systems,
for International Airports in Malaysia: A Systematic
Communications and Computers, IEEE, pp. 161-166,
Literature Review (SLR)." Journal of Information
2022.
and Knowledge Management (JIKM), Vol. 2,
[70]
R. A. Ramadan, B. W. Aboshosha, J. S. Alshudukhi,
pp. 156-167, 2023.
A. J. Alzahrani, A. El-Sayed, and M. M. Dessouky.
[61]
E. Ukwandu, M. Ben-Farah, H. Hindy, M. Bures,
"Cybersecurity and Countermeasures at the Time
R. Atkinson, C. Tachtatzis, I. Andonovid, and
of Pandemic." Journal of Advanced Transportation,
X. Bellekens. "Cybersecurity Challenges in Aviation
Vol. 2021, No. 1, 2021.
Industry: A Review of Current and Future Trends."
[71]
Trend Micro, The case for making BYOD safe-
Information, Vol. 13, No. 3, 2022.
security news. Available Online at https://www.
[62]
trendmicro.com/vinfo/us/security/news/internet-
L.F. Benítez. "Identifying Cyber Security Risks in
62 วารสารเทคโนโลยีีสารสนเทศ มจพ.
Information Technology Journal KMUTNB
Spanish Airports." Cyber Security: A Peer-Reviewed
ปีี ที่่� 21 ฉบัับที่่� 2 กรกฎาคม - ธัันวาคม 2568 Vol. 21, No. 2, July - December 2025
Research Paper: Safeguarding Skies: Airport Cybersecurity in the Digital Age
of-things/the-case-for-making-byod-safe, accessed on
[80]
S. Sivakorn, A. D. Keromytis, and J. Polakis.
1 February 2024.
"That's the Way the Cookie Crumbles: Evaluating
[72]
C. Brook, The Ultimate Guide to BYOD Security:
HTTPS Enforcing Mechanisms." Proceedings of
Definition & More. Available Online at https://
the 2016 ACM on Workshop on Privacy in the
digitalguardian.com/blog/ultimate-guide-byod-security-
Electronic Society, 2016.
overcoming-challenges-creating-effective-policies-
[81]
S. Sivakorn, P. Sirawongphatsara, and N. Rujiratanapat.
and-mitigating, accessed on 1 June 2023
"Web Encryption Analysis of Internet Banking
[73]
A. Bridgwater, How mobile device management is
Websites in Thailand." Proceedings of the 17th
taking on the BYOD challenge. Available Online at
International Joint Conference on Computer Science
https://www.theregister.com/2014/11/08/mobile
and Software Engineering, pp. 139-144, 2020.
working/, accessed on 1 June 2023.
[82]
M. Kacic, P. Hanacek, M. Henzl, and P. Jurnecka.
[74]
Y. Joshi, D. Das, and S. Saha. "Mitigating Man in
"Malware Injection in Wireless Networks."
the Middle Attack Over Secure Sockets Layer."
Proceedings of the 7th International Conference on
Proceedings of the 2009 IEEE International Conference
on Internet Multimedia Services Architecture and
Systems, Vol. 01, pp. 483-487. 2013.
Applications (IMSAA), pp. 1-5, 2009.
[83]
A. Zimba, Z. Wang, and M. Mulenga. "Cryptojacking
[75]
M. Marlinspike, New Tricks for Defeating SSL in
Injection: A Paradigm Shift to Cryptocurrency-based
Practice. Black Hat USA, Available Online at
Web-centric Internet Attacks." Journal of Organizational
https://www.blackhat.com/presentations/bh-dc-09/
Computing and Electronic Commerce, Vol. 29,
Marlinspike/BlackHat-DC-09-Marlinspike-
pp. 40-59, 2019.
Defeating-SSL.pdf, accessed on 1 June 2023.
[84]
J. Spaulding, A. Krauss, and A. Srinivasan.
[76]
Norton, Public Wi-Fi: An Ultimate Guide on the
"Exploring an Open WiFi Detection Vulnerability as
Risks + How to Stay Safe. Available Online at
a Malware Attack Vector on iOS Devices."
Intelligent Data Acquisition and Advanced Computing
https://us.norton.com/blog/privacy/public-wifi,
Proceedings of the 7th International Conference on
accessed on 1 February 2024.
Malicious and Unwanted Software, pp. 87-93, 2012.
[77]
S. Englehardt, D. Reisman, C. Eubank, et al.
[85]
Krebson Security, Why is 'Juice Jacking' Suddenly
"Cookies that Give You Away: The Surveillance
Back in the News?. Available Online at https://
Implications of Web Tracking." Proceedings of the 24th
krebsonsecurity.com/2023/04/why-is-juice-jacking-
International Conference on World Wide Web,
suddenly-back-in-the-news/, accessed on 1 February 2024.
Florence, Italy, pp. 289-299, 2015.
[86]
Kaspersky, What is an Evil Twin Attack? Evil Twin
[78]
X. Zheng, J. Jiang, J. Liang, et al. "Cookies Lack
Wi-Fi Explained. Available Online at https://www.
Integrity: Real-World Implications." Proceedings of
kaspersky.com/resource-center/preemptive-safety/
the 24th USENIX Security Symposium, Washington, D.C,
evil-twin-attacks, accessed on 1 February 2024.
pp. 707-721, 2015.
[87]
V. Roth, W. Polak, E. G. Rieffel, and T. Turner.
[79]
S. Sivakorn, I. Polakis, and A. D. Keromytis.
"Simple and Effective Defense Against Evil Twin
"The Cracked Cookie Jar: HTTPS Cookie Hijacking
Access Points." Wireless Network Security,
and the Exposure of Private Information."
pp. 220-235, 2008.
Proceedings of the 2016 IEEE Symposium on Security
[88]
H. Gonzales, K. Bauer, J. Lindqvist, D. McCoy,
and D. Sicker. "Practical Defenses for Evil Twin
and Privacy, pp. 724-742, 2016.
ปีี ที่่� 21 ฉบัับที่่� 2 กรกฎาคม - ธัันวาคม 2568
Vol. 21, No. 2, July - December 2025
วารสารเทคโนโลยีีสารสนเทศ มจพ. 63
Information Technology Journal KMUTNB
Research Paper: Safeguarding Skies: Airport Cybersecurity in the Digital Age
Attacks in 802.11." Proceedings of the 2010 IEEE Global
[99]
SecureList, DarkVishnya: Banks attacked through
Telecommunications Conference GLOBECOM 2010,
direct connection to local network. Available Online at
pp. 1-6, 2010.
https://securelist.com/darkvishnya/89169/,
[89]
Palo Alto Networks, What Is Network Segmentation?.
accessed on 1 February 2024.
Available Online at https://shorturl.at/rCIDK,
[100]
SecureWorks, Gold Sahara. Available Online at
accessed on 1 June 2023.
https://www.secureworks.com/research/threat-profiles/
[90]
The Local Austria, Turkish suspect identified in Vienna
gold-sahara, accessed on 1 February 2024.
airport cyberattack. Available Online at https://
[101]
Google, Turla: A Galaxy of Opportunity. Available
www.thelocal.at/20170228/suspect-identified-in-vienna,
Online at https://cloud.google.com/blog/topics/threat-
accessed on 1 June 2023
intelligence/turla-galaxy-opportunity, accessed on
[91]
H. Abbas, N. Emmanuel, M. F. Amjad, et al.
1 February 2024.
"Security Assessment and Evaluation of VPNs:
[102]
CANSO, CANSO Standard of Excellence in Cybersecurity.
A Comprehensive Survey." ACM Computing Surveys,
Available Online at https://canso.org/publication/
Vol. 55, No. 13s, pp.1-47, 2023.
canso-standard-of-excellence-in-cybersecurity/,
[92]
CISA, 2021 Top Routinely Exploited Vulnerabilities.
accessed on 1 February 2024.
Available Online at https://www.cisa.gov/news-
[103]
Airports of Thailand (AOT), AOT ICT Security Policy,
events/cybersecurity-advisories/aa22-117a,
AOT Cyber Security Policy and AOT Personal
accessed on 1 June 2023.
Data Protection Policy. Available Online at https://
[93]
TechTarget, The Mirai IoT Botnet holds strong in 2020.
corporate.airportthai.co.th/th/cybersecurity-th/,
Available Online at https://shorturl.at/GMUA8,
accessed on 1 February 2024.
accessed on 1 June 2023.
[104]
TSA, TSA issues new cybersecurity requirements
[94]
Keyfactor, Top 10 IoT Vulnerabilities in Your Devices.
for airport and aircraft operators. Available Online at
Available Online at https://www.keyfactor.com/
https://shorturl.at/eXlvZ, accessed on 1 June 2023.
blog/top-10-iot-vulnerabilities, accessed on 1 June 2023.
[105]
T. Szuba. Safeguarding Your Technology: Practical
[95]
Bloomberg, China Used a Tiny Chip in a Hack
Guidelines for Electronic Education Information
That Infiltrated U.S. Companies. Available Online at
Security. National Center for Education Statistics, 1998.
https://shorturl.at/tMHdW, accessed on 1 February 2024.
[106]
ICAO, Annex 17 - Aviation Security, ICAO - International
[96]
WIRED, Hacker Lexicon: What Is a Supply Chain
Standards and Recommended Practices. Available
Attack?. Available Online at https://www.wired.
Online at https://shorturl.at/JQHkr, accessed on
com/story/hacker-lexicon-what-is-a-supply-chain-
1 February 2024.
attack/, accessed on 1 June 2023.
[107]
ICAO, AVIATION CYBERSECURITY. (2022),
[97]
M. Theoharidou, S. Kokolakis, M. Karyda, and
Available Online at https://www.icao.int/aviation
E. A. Kiountouzis. "The insider threat to information
cybersecurity/Pages/default.aspx, accessed on
systems and the effectiveness of ISO17799."
1 February 2024.
Computers & Security, Vol. 24, pp. 472-484, 2005.
[108]
S.-J. Lee, H.Y. Shim, Y.R. Lee, T.R. Park, S.H. Park,
[98]
MITRE. MITRE ATT&ACK Matrix for Enterprise.
and I.G. Lee. "Study on Systematic Ransomware
Available Online at https://attack.mitre.org/,
Detection Techniques." Proceedings of the 24th
accessed on 1 September 2024.
International Conference on Advanced Communication
Technology (ICACT), pp. 297-301. 2022
64 วารสารเทคโนโลยีีสารสนเทศ มจพ.
Information Technology Journal KMUTNB
ปีี ที่่� 21 ฉบัับที่่� 2 กรกฎาคม - ธัันวาคม 2568 Vol. 21, No. 2, July - December 2025
Research Paper: Safeguarding Skies: Airport Cybersecurity in the Digital Age
[109]
MITRE, MITRE ATT&CK Matrix - Data Encrypted
org/techniques/T1498/, accessed on 1 February 2024.
for Impact. Available Online at https://attack.mitre.
[113]
WIRED, GitHub Survived the Biggest DDoS Attack
org/techniques/T1486/, accessed on 1 February 2024.
Ever Recorded. Available Online at https://www.
[110]
J. Katz. "Universally Composable Multi-party
wired.com/story/github-ddos-memcached/,
Computation using Tamper-proof Hardware."
accessed on 1 February 2024.
Advances in Cryptology – EUROCRYPT 2007,
[114]
I. A. Shah, N. Jhanjhi, and S. Brohi. "Cybersecurity
pp. 115-128, 2007.
Issues and Challenges in Civil Aviation Security."
[111]
R. Gennaro, A. Lysyanskaya, T. Malkin, S. Micali,
Cybersecurity in the Transportation Industry,
and T. Rabin. "Algorithmic Tamper-proof (ATP)
pp. 1-23, 2024.
Security: Theoretical Foundations for Security
[115]
D. S. Turetsky, B. H. Nussbaum, and U. Tatar.
Against Hardware Tampering." Theory of Cryptography
Success Stories in Cybersecurity Information Sharing.
Conference TCC 2004, 2004.
The College of Emergency Preparedness, Homeland
[112]
MITRE, MITRE ATT&CK Matrix - Network Denial
Security and Cybersecurity University at Albany, 2020.
of Service. Available Online at https://attack.mitre.
ปีี ที่่� 21 ฉบัับที่่� 2 กรกฎาคม - ธัันวาคม 2568
Vol. 21, No. 2, July - December 2025
วารสารเทคโนโลยีีสารสนเทศ มจพ. 65
Information Technology Journal KMUTNB