ConceptioArchivearXiv CS
arXiv CSopen access

Safeguarding Skies: Airport Cybersecurity in the Digital Age

Unknown · 2026 · arxiv_cs
arXiv CS · Papers · License: Open Access · 2026
Open Source ↗Direct PDF ↓
cryptographycybersecurityprivacysecurity
cryptography, security, privacy, cybersecurity

Research Paper: Safeguarding Skies: Airport Cybersecurity in the Digital Age

Safeguarding Skies: Airport Cybersecurity in the Digital Age Suphannee Sivakorn*, Nuttaya Rujiratanapat*, Yotsapat Ruangpaisarn*, Chanond Duangpayap* and Sakulchai Saramat* Received: March 6, 2024 Revised: November 16, 2024 Accepted: November 25, 2024 * Corresponding Author: Suphannee Sivakorn, E-mail: [email protected] DOI: 10.14416/j.it/2025.v2.005

Abstract

ensure their security practices meet current standards.

The aviation industry faces significant vulnerabilities

However, in the realm of technology, cybersecurity often receives

from both physical and cybersecurity threats, highlighting

inadequate attention than physical security, as evidenced by

the urgent need for enhanced cybersecurity measures amid

a 2017 survey of the top major airports in Europe and the U.S.,

increasingly sophisticated attacks. This paper systematically

wherein only 59% of respondents claimed to have an effective

reviews emerging threats at airports, analyzing real-world

cybersecurity policy [1]. This oversight is concerning,

incidents and relevant literature while mapping risks to

especially given a 530% increase in cyberattacks within

the MITRE ATT&CK Matrix, a widely recognized knowledge

the aviation industry from 2019 to 2022 [2]. Recent initiatives

base for categorizing cyberattack tactics, techniques,

by authorities, including the Transportation Security

and procedures. This is the first to apply the MITRE Matrix to

Administration (TSA) and the International Air Transport

airport security risks, offering a novel approach to understanding

Association (IATA), emphasize the need for enhanced

and mitigating these challenges. Building on this analysis,

cybersecurity measures, mandating proactive steps to mitigate

the paper advocates for modern cybersecurity defense models,

cyber threats [3], [4].

emphasizing Cybersecurity Frameworks and Zero Trust

In an effort to strengthen the cybersecurity posture of

Architecture, as well as critical measures for supply chain

the aviation industry, this study comprehensively explores

risk management and strategies to mitigate ransomware and

existing literature and recent data on airport cybersecurity.

DoS attacks. Our analysis provides insights into vulnerabilities

We examine airport technologies, security concerns,

and actionable recommendations, serving as a comprehensive

and recent cyber incidents in Section 2, and outline our research

guide for aviation stakeholders to strengthen defenses against

methodology in Section 3. Section 4 presents a systematic

evolving cybersecurity threats.

literature review of airport cybersecurity from the past five years, and Section 5 categorizes the current landscape and identifies

Keywords: Airport Cybersecurity, Aviation Cybersecurity,

relevant risks. We map these risks to the MITRE ATT&CK

Cyber Threats in Aviation, Critical Infrastructure, Smart Airport.

Matrix for Enterprise, a widely recognized cybersecurity knowledge base for developing effective security strategies in

1. Introduction

Section 6. Section 7 presents modern cybersecurity defense

In the physical domain, airport security entails the screening

strategies, advocating for Cybersecurity Frameworks and

of passengers, baggage, cargo, and the fortification of secure

Zero Trust Architecture and highlights essential measures

areas within the airport premises. Airport authorities undertake

for mitigating supply chain risks, ransomware, and denial-of-

substantial efforts to prevent unlawful interference and

service (DoS) attack. Section 8 discusses key challenges

* Department of Computer Science, Faculty of Science and Technology, Rajamangala University of Technology Tawan-ok

ปีี ที่่� 21 ฉบัับที่่� 2 กรกฎาคม - ธัันวาคม 2568

Vol. 21, No. 2, July - December 2025

วารสารเทคโนโลยีีสารสนเทศ มจพ. 47

Information Technology Journal KMUTNB

Research Paper: Safeguarding Skies: Airport Cybersecurity in the Digital Age

and outlines future research directions in this field, with

Airport 3.0 or "Smart Airport" integrates the Internet

the conclusion presented in Section 9.

of Things (IoT), Artificial Intelligence, smart sensors to

The major contributions of this paper are as follows:

enhance passenger experience [8].

We conducted an extensive analysis of recent

Airport 4.0 emphasizes the use of technologies to support

cyberattacks and a literature review from the past

airport operations and enhance passenger experiences,

five years, categorizing key cybersecurity risks

with a focus on data analytics as a core capability [9], [10].

into nine distinct areas to clarify the challenges

While these airport advancements offer notable benefits,

faced by modern airport operations.

they are susceptible to interference and malicious modification

We correlate these identified risks with the MITRE

without proper deployment.

ATT&CK Matrix for Enterprise, making this paper

2.2 Airport Cyber Threat Actors

the first to map airport security risks to the Matrix.

Incidents of air terrorism have led adversaries to adapt

This serves as a valuable tool for exploring each

their tactics in both physical and cyber domains [7].

risk through practical defenses and best practices

This section outlines four types of cyber threat actors:

outlined in the MITRE knowledge base.

1: Advanced Persistent Threat (APT): Organized groups

Based on our analysis, we advocate for adopting

or foreign governments motivated by political or economic goals.

modern security practices, including Cybersecurity

They often target critical infrastructure, including airports

Frameworks and Zero Trust Architecture, along

[11] - [16].

with practical measures to defend against evolving

airport cyber threats.

2: Cybercrime: Attackers in this category target systems for valuable and sensitive information from passengers and airport employees [17] - [21], particularly those that are

2. Background

internet-facing or publicly accessible [17].

Understanding airport technologies, threat actors,

3: Peer Group Service Disruption: Hackers motivated by

and recent high-profile incidents highlights the need for stronger

political agendas or beliefs whose focus is on service disruptions

security measures. This section examines airport technology,

rather than data theft and financial gain [22] - [30].

cybersecurity concerns, the landscape of cyber threat actors, and notable attack incidents.

4: Insider Threats: Risks that originate from within the organization, typically associated with current or former

2.1 Airport Technology and Security Concerns

members of the organization, it may also arise from third parties

Airport operations have transformed significantly to support

such as contractors and temporary workers.

the global aviation industry growth, leading to advancements in

2.3 Recent Notable Cybersecurity Incidents

technology aimed at enhancing efficiency and service.

The urgency of cybersecurity in airports has become

The evolution of airport technology is delineated into four stages:

apparent through numerous studies [1], [5], [8]. From 2022

Airport 1.0 - 4.0.

to 2024, various notable incidents have highlighted cyberattacks

Airport 1.0 primarily focuses on ensuring the physical safety of operations, with no security concerns [5].

affecting airport operations and public perception. Table 1 details and categorizes these incidents by attack type,

Airport 2.0 incorporates technologies for collaboration

including Denial-of-Service, Ransomware, Vulnerability

technologies such as IP telephony, broadband, and Wi-Fi [6].

Exploitation, and Phishing. This analysis will assist in identifying

Following the events of 9/11, the TSA was established to

cybersecurity risks and associated attack vectors for airports

oversee transport security [7].

in Section 5.

48 วารสารเทคโนโลยีีสารสนเทศ มจพ.

Information Technology Journal KMUTNB

ปีี ที่่� 21 ฉบัับที่่� 2 กรกฎาคม - ธัันวาคม 2568 Vol. 21, No. 2, July - December 2025

Research Paper: Safeguarding Skies: Airport Cybersecurity in the Digital Age

Denial-of-Service (DoS). Recently, several major

4. Literature Review

U.S. airports were targeted by coordinated DoS attacks [29],

We conduct a comprehensive literature review by searching

which overloaded airport servers. Similar incidents have

academic databases, including Google Scholar, ResearchGate,

occurred at various airports worldwide [23] - [31]. In some

Scopus, and Web of Science, using the following keywords:

cases, attackers have demanded cryptocurrency payments to

"airport AND cybersecurity", "aviation AND cybersecurity",

stop the attacks, exploiting the difficulty of tracing such

"airport AND information security", "airport AND IT security",

transactions [32].

"smart airport", and "airport AND cyber risk". Our focus

Ransomware. The airport industry has experienced

was on peer-reviewed studies from the last five years addressing

a significant increase in ransomware attacks, primarily due to

the impacts of cybersecurity on modern airports, challenges,

system vulnerabilities and phishing attempts [33] - [35], [38].

and risks, while excluding studies on airport physical security

In 2024, notable incidents led to delays in passenger processing

or unrelated aviation topics. In total, we reviewed 31 publications,

and flight schedules [34], [35], while others resulted in

categorizing them into eight primary areas: (1) Critical

the leakage of sensitive data [33].

Infrastructure, (2) IoT, Smart Devices, and AI Technology,

Vulnerability Exploitation poses significant risks for

(3) Supply Chain, (4) Cybersecurity Awareness, (5) Risk

airports, which rely on variety of software applications for their

and Threat Analysis, (6) Standards and Regulations,

operations, ranging from flight scheduling, air traffic control,

(7) Cybersecurity Framework, and (8) Case Studies and Surveys.

baggage handling, and security systems [1], [5], [8].

Table 2 presents the number of publications in each category

This diversity broadens the attack surface, introducing potential

and highlights specific airport security risks where applicable.

vulnerabilities and inadequate security practices from vendor

Critical Infrastructure. This category focuses on the critical

[17], [19], [20] - [22], [25], [36], [37].

infrastructures of airports, such as communication protocols,

Phishing. Although no new incidents have been disclosed

Air Traffic Management (ATM), and surveillance technologies

recently, phishing remains a significant threat with airport

[41] - [47]. These studies analyze vulnerabilities and mitigations,

employees and customers vulnerable to scams [38]. During

with examples including man-in-the-middle attacks between

a recent global outage linked to CrowdStrike [39], opportunistic

aircraft and ground control [42], the lack of encryption in

hackers exploited the situation by sending fake information to

the Automatic Dependent Surveillance-Broadcast (ADS-B)

scam IT personnel [40].

[43], [45], and the security concerns related to digitization of the Traffic Collision Avoidance System (TCAS) [44].

3. Research Methodology

These findings underscore the need to address cybersecurity

This study synthesizes recent airport cybersecurity incidents,

risks in airports. To this end, we associate these publications

literature, insights from online sources, and an examination of

related to airport security risks as follows: (1) Insecure Network

various cybersecurity standards and policies. Our goal is to

Architecture, (2) Malware and Ransomware (3) Data Breach

identify and delineate the prevailing cybersecurity threats

and (4) DoS.

and risks, categorizing them in alignment with the MITRE

IoT, Smart Devices, and AI Technology. Research here

ATT&CK Matrix. By systematically mapping these risks to

addresses cybersecurity risks from IoT devices and AI

the Matrix, we provide a strategic approach for mitigating

technologies used in airport operations [1], [5], [8], [48] - [50].

cybersecurity risks and applying effective defense techniques

Consequently, we associate these publications with specific risks,

based on current best practices.

including: (1) Public-facing Access, (2) Insecure Network Architecture, (3) Internet-facing Applications and Services,

ปีี ที่่� 21 ฉบัับที่่� 2 กรกฎาคม - ธัันวาคม 2568

Vol. 21, No. 2, July - December 2025

วารสารเทคโนโลยีีสารสนเทศ มจพ. 49

Information Technology Journal KMUTNB

Research Paper: Safeguarding Skies: Airport Cybersecurity in the Digital Age

Table 1. Summary of Publicly Disclosed Notable Cybersecurity Incidents at Airports (2022-2024). Impact on Airport Services Attack Incident

Attack Incident Summary

Year

Attack Technique

Operational Disruption

Website or Application

Data Leakage

Threat Actor Type*

Seattle Airport [33]

The Port of Seattle confirmed that a ransomware attack caused significant outages at Seattle-Tacoma International Airport, affecting services like Wi-Fi, check-in kiosks, and passenger displays. The attack also resulted in some data being stolen and encrypted

2024

Ransomware

Pau-Pyre ́́ne ́́es Airport [34]

Pau-Pyre ́ ́ne ́ ́es Airport was hit by a ransomware attack from the MONTI group, which exfiltrated sensitive data and published it on the dark web.

2024

Ransomware

Croatia’s Split Airport [35]

Split Airport in Croatia experienced a ransomware attack that resulted in flight cancellations and delays. The incident has been linked to the Akira group, which is associated with the Russian-based Conti group.

2024

Ransomware

Los Angeles International Airport [36]

A hacker group, IntelBroker, exploited the airport's CRM system vulnerability, accessing a database with sensitive information (e.g., private plane owners' full names, emails, CPA numbers)

2024

Vulnerability Exploitation

Copenhagen Airport [31]

The airport website was taken offline. Passengers were advised to use their smartphones as an alternative to receive updates on their flights.

2024

DoS

Beirut International Airport [17]

Hackers displayed a message on screens at the airport threatening to bomb the airport.

2024

unknown

Long Beach Airport [18]

Part of Long Beach City system cyberattack. The website was taken offline.

2023

Ransomware

2

Cairo International Airport [23]

The airport website and mobile application were taken down. Anonymous Collective hacker group took credit for the attack.

2023

DoS

3

Czech and Prague Airport [24]

The airport website was taken offline.

2023

DoS

3

Quere ́́taro Intercontinental Airport [19]

LockBit ransomware hacker group took credit for the attack, threatening to leak data. The airport claimed that stolen data was in the public domain.

2023

Ransomware

MontrealTrudeau International Airport [25]

Border checkpoint outages e.g., check-in kiosks and electronic gates caused significant delays. A hacker group, NoName057(16) claimed responsibility.

2023

DoS

Charles de Gaulle Airport [26]

The airport website was taken offline. Cybercriminal, Dark Storm, claimed responsibility.

2023

DoS

3

UK Airports [27]

The airport website was taken offline. UserSec hacker group claimed the responsibility.

2023

DoS

3

Kenya Airports Authority [20]

Data breach incident. Attackers released data including procurement plans, physical plans, site surveys, invoices and receipts.

2023

unknown

German Airports [28]

Several German airports’ websites were taken offline.

2023

DoS

3

US Major Airports [29]

Coordinated DoS attacks targeted several major US airports. A hacker group, Killnet claimed responsibility.

2022

DoS

3

Brazil Airports [37]

Rio de Janeiro airport’s electronic displays were hacked to show pornographic movies instead of ads and flight info.

2022

Vulnerability Exploitation

Italian Airports [30]

Coordinated DoS attacks targeted several Italian airports. A hacker group, Killnet claimed responsibility.

2022

DoS

Swissport at Zurich Airport [21]

Airport ground services and air cargo, Swissport, were hit with a ransomware attack causing Zurich Airport operation disruptions.

2022

Ransomware

2

2

2

unknown

3

2

3

2

unknown •

2

3 2

The sign ● indicates the impact on airport services from the attack. *The Threat Actor Type number delineates the category of cyber threat actors in Section 2.2

50 วารสารเทคโนโลยีีสารสนเทศ มจพ.

Information Technology Journal KMUTNB

ปีี ที่่� 21 ฉบัับที่่� 2 กรกฎาคม - ธัันวาคม 2568 Vol. 21, No. 2, July - December 2025

Research Paper: Safeguarding Skies: Airport Cybersecurity in the Digital Age

(4) Malware and Ransomware, (5) Data Breach, and

systematically manage risks and enhance resilience.

(6) DoS as these threats exploits internet connectivity used by

While many studies agree the necessity of these frameworks

IoT and smart devices. Furthermore, vulnerabilities in these

[1], [5], [8], [41], [55], [67], [68] for example, adopting

products can lead to supply chain attacks [51].

the National Institute of Standards and Technology's (NIST)

Supply Chain and Third Party. This category examines

Cybersecurity Framework to comply with ICAO standards [55],

cybersecurity vulnerabilities arising from supply chain and

only few recent publications [55], [67], [68] provide

third-party partnerships. For example, Hann (2020) emphasized

actionable details. Nevertheless these frameworks often lack

the complex socio-technical landscape of the ATM System [47],

comprehensive insights into adversary behavior, which are

emphasizing the need for attention to sectors critical to

essential for identifying and responding to threats throughout

airport operations, particularly in the context of digital cyber

an attack's lifecycle. Further details will be provided in Section 6.

warfare [51], as discussed.

Case Study and Survey. This category focuses on research

Cybersecurity Awareness. This category investigates

examining the cybersecurity posture of specific airports.

the effectiveness of cybersecurity awareness training within

Publications may present case studies based on geography

airport environments. While numerous studies have highlighted

[60], [62], [63], or specific events [69], [70] like the COVID-19

the significance of cybersecurity awareness training [1], [5], [8].

pandemic [70] to gather insights on cybersecurity practices

However, only one recent publication by Sabillon et al. (2023) [52]

and challenges.

has thoroughly examined this topic. We categorize these publications under the following risks: (1) Social Engineering, (2) Insider Threats, and (3) Data Breach, as these risks often arise from human [1], [5], [8], [52] - [54]. Risk and Threat Analysis. This research category conducts

5. Airport Security Risks This section provides detailed exploration of cybersecurity risks associated with attack vectors (Section 2.3) and those identified in our literature review (Section 4).

literature reviews to identify risks and threats affecting airports.

5.1 Public-facing Accesses

Studies provide insights into threats and recommend

BYOD. The practice of Bring-Your-Own-Device (BYOD)

improvements for threat detection and response [41], [43], [49],

commonly raises concern due to the exposure of organizations to

[55] - [64]. Numerous works study airport cybersecurity

vulnerabilities [71], [72]. However, in airport settings,

incidents [55] - [60], including threat actor typologies [58], [61]

passengers commonly use their personal devices. The diversity of

and associated risks and threats in relation to ICAO (International

connected devices in this context complicates device

Civil Aviation Organization) standards [55], which encompass

management [73], heightening the security risk when these

the entire spectrum of airport security risks.

devices connect to airport networks.

Standards and Regulations. Publications in this category

Public Access Services such as Wi-Fi access, check-in kiosks,

review existing cybersecurity standards and regulations

and charging stations enhance the passenger experience [6],

pertinent to the aviation sectors [63] - [66]. They study challenges

but they also increase risks by leaving users vulnerable to

and gaps in airport cybersecurity policies posed by rapid

cyberattacks [74] - [76], particularly if proper network

technological development and call for international

segmentation is not implemented.

cooperation and standardized policies, which currently remain insufficient [64].

Man-in-the-Middle (MITM) attacks are prevalent on public Wi-Fi, where cybercriminals eavesdrop using network

Cybersecurity Framework. This category investigates

snooping and sniffing tools to steal sensitive information

frameworks tailored for airports, focusing on models that

[75], [77]–[79]. Despite this, many critical websites continue to

NIST Cybersecurity Framework: https://www.nist.gov/cyberframework 1

ปีี ที่่� 21 ฉบัับที่่� 2 กรกฎาคม - ธัันวาคม 2568

Vol. 21, No. 2, July - December 2025

serve content over unencrypted connections [79] - [81].

วารสารเทคโนโลยีีสารสนเทศ มจพ. 51

Information Technology Journal KMUTNB

Research Paper: Safeguarding Skies: Airport Cybersecurity in the Digital Age

Table 2. Airport Cybersecurity Publications by Category and Associated Security Risks.

List of Publications

Number of Publications

[41] - [47]

9

Insecure Network Architecture Malware and Ransomware Data Breach DoS

[1], [5], [8], [48] - [50]

6

Public-facing Access Insecure Network Architecture Internet-facing Applications and Services Malware and Ransomware Data Breach Supply Chain and Third Party DoS

Supply Chain and Third Party

[47]

1

Supply Chain and Third Party

Cybersecurity Awareness

[52]

1

Social Engineering Insider Threats Data Breach

Risk and Threat Analysis

[41], [43], [49], [55] - [64]

13

Public-facing Access Insecure Network Architecture Internet-facing Applications and Services Social Engineering Malware and Ransomware Data Breach Supply Chain and Third Party Insider Threat DoS

Standard and Regulation

[63] - [66]

4

(inapplicable)

Cybersecurity Framework

[55], [67], [68]

3

(inapplicable)

Case Study and Survey

[60], [62], [63], [69], [70]

5

(inapplicable)

31

Public-facing Access Insecure Network Architecture Internet-facing Applications and Services Social Engineering Malware and Ransomware Data Breach Supply Chain and Third Party Insider Threat DoS

Publication Category Critical Infrastructure

IoT, Smart Devices and AI Technology

Total

Associated Security Risks (when applicable)

Malicious Hotspots. A malicious hotspot, also known as a "rogue access point" poses a significant threat to public Wi-Fi users. The attacker sets up a wireless access point with an identical SSID to deceive users, making users vulnerable to MITM or other network attacks [86] - [88]. 5.2 Insecure Network Architecture Figure 1. Basic Network Segmentation for Airport Security.

An insecure network architecture may allow attackers to

Malware from Untrusted Devices. In this attack,

gain access to internal systems and move laterally across

bad actors aim to inject malicious payload onto Wi-Fi users'

organization assets. Effective network segmentation is a key

devices [82], [83]. Adversaries may target vulnerabilities on

component, enabling administrators to manage network

popular devices, e.g., iOS [84]. Public charging stations also

interactions more securely by implementing security policies,

pose risks, known as "juice jacking", where attackers use

with varying levels of security and trust assigned to different

these stations to spread malware and extract data from

applications [89]. Figure 1 illustrates a basic example of network

smartphones [85].

segmentation applicable to an airport, where each segment

52 วารสารเทคโนโลยีีสารสนเทศ มจพ.

Information Technology Journal KMUTNB

ปีี ที่่� 21 ฉบัับที่่� 2 กรกฎาคม - ธัันวาคม 2568 Vol. 21, No. 2, July - December 2025

Research Paper: Safeguarding Skies: Airport Cybersecurity in the Digital Age

requires specific measures and is separated based on the different

phishing emails designed to deceive users into disclosing

entities and stakeholders involved, which can be described

financial information [61]. Some of these attacks predominantly

as follow:

target employees with privileged access to critical systems [8].

Public Wi-Fi. To prevent potential malicious activities

5.5 Malware and Ransomware

spreading to other airport entities such as CCTV systems [1]

Ransomware incidents often lead to airport operational

and malware incidents at Vienna Airport [90], it should be

disruptions and passenger experience [18], [19], [21], [33] - [35].

completely segregated from other airport networks.

Additionally, malware attacks may lead to data breaches,

IoT Devices. IoT devices often rely on vendor or

exposing sensitive information such as passenger records,

third-party-based solutions, making them vulnerable to

payment details, and employee credentials [31], [32].

third-party security risks (Section 5.7). Consequently, it is

Such breaches jeopardize privacy and can incur financial costs

recommended to isolate them from other networks, particularly

for airports, including remediations and regulatory fines.

critical networks.

5.6 Data Breach

Back Office is responsible for the administration, operations

Data breaches often results in the unauthorized access,

and logistics of the airport. Given the human-centric nature of

disclosure, or theft of sensitive information [19], [20], [33],

these operations, this network is prone to risks such as phishing,

[34], [36]. Additionally, breaches of sensitive operational

social engineering, and other human errors. This network

information can undermine airport operations and lead to

should be kept separated for added security.

security vulnerabilities [20]. In some cases, attackers may

Critical Infrastructures includes crucial assets for

exfiltrate data and demand ransom for its return or for

the airport operations. Access to this network should be

the decryption of compromised systems [32].

restricted from the public network, robust authentication and

5.7 Supply Chain and Third-Party

encryption measures must be implemented, as highlighted in

Security Vulnerabilities in systems can allow attackers to

several studies discussed in Section 4.

gain unauthorized access. These weaknesses may stem from

5.3 Internet-facing Applications and Services

known or unknown third-party software and hardware bugs, and

Security Vulnerabilities. Adversaries often exploit

misconfigurations [92]. Zero-day vulnerabilities pose particular

weaknesses in internet-facing applications such as airport

risks, as attacks can occur before developers issue patches.

websites, and mobile applications. These vulnerabilities can

Concerns about IoT and vendor solution vulnerabilities are

arise from software bugs, design flaws, or unpatched

amplified by the potential for threat actors to compromise

vulnerabilities, as discussed in Section 2.3 and Section 4.

not only the affected device but also other network assets [93].

Weak authentication practices in internet-facing

No Security Update Mechanism. Many solutions,

applications pose significant risks for airports, potentially

particularly IoT devices, may lack a security update mechanism,

leading to unauthorized access to critical systems. Additionally,

leaving them vulnerable even after patches have been

remote access for employees can further complicate security;

released [94].

if authentication credentials are weak, attackers may gain broader access to internal networks [91].

No Common Standards and Specifications. The lack of universally accepted standards for IoT device development

5.4 Social Engineering

leads to inconsistent implementations and design choices,

Phishing. Social engineering attacks exploit human

which negatively affect security. Users must manage multiple

vulnerabilities, with phishing being a significant concern. In 2013, over 75 U.S. airports reported incidents involving

ปีี ที่่� 21 ฉบัับที่่� 2 กรกฎาคม - ธัันวาคม 2568

Vol. 21, No. 2, July - December 2025

technologies to effectively support these devices [5]. Supply Chain Compromise involves manipulating products

วารสารเทคโนโลยีีสารสนเทศ มจพ. 53

Information Technology Journal KMUTNB

Research Paper: Safeguarding Skies: Airport Cybersecurity in the Digital Age

before they reaches consumer, creating vulnerabilities in

arising from these identified risks.

critical systems. For example, compromised chips or drivers

6.1. MITRE Matrix: TTPs

in smart devices at airports can expose systems to attack [95].

The MITRE Matrix categorizes attacker tactics and techniques.

High-profile incidents, such as the SolarWinds hack, affected

Each tactic represents a high-level goal, while the techniques

over 18,000 networks globally [96]. Additionally, a recent

describe the specific methods employed to achieve that goal,

incident in Lebanon further illustrates the dangers, where

both indexed for easy reference. Each technique includes

devices were reportedly manipulated for digital warfare [51].

(1) procedures based on real-world incidents, (2) mitigations

No Physical Hardening. IoT devices are often deployed in

with actionable defense recommendations such as configurations

various locations throughout the airport, making them

and tools, and (3) detection strategies and recommendations

vulnerable to tampering during unattended operations.

for identifying the attacks. We believe that this comprehensive

Physical access can result in theft and unauthorized access to

information enables airport security personnel to effectively

internal circuits and overwriting changes [1].

implement strategies to mitigate identified risks.

5.8 Insider Threat

6.2 Airport Security Risks with the MITRE Matrix

An insider threat is a security risk posed by individuals

The MITRE Matrix is a valuable tool for identifying and

who misuse their access or privileged accounts. A malicious

mapping airport security risks related to potential attacks.

insider, often referred to as a "Turncloak," intentionally abuses

Given the complexity of vulnerabilities, some risks may align

legitimate access to steal sensitive information or manipulate

with multiple MITRE techniques. This paper focuses on

critical aviation systems. Mitigating this threat involves

two key tactics: Initial Access (TA001) and Impact (TA0040).

adhering to information security management standards and

Initial Access is fundamental as it represents the first step for

guidelines [97].

adversaries to gain entry into protected systems. The Impact

5.9 Denial-of-Service

tactic, particularly T1498 (Network Denial of Service), is

As outlined in Section 2, DoS attacks on airport websites are

emphasized due to its prevalence due to its frequency in recent

significant threats to the aviation sector, with recent treads

incidents discussed in Section 2.3.

showing demands ransom payments to stop these attacks, aided by the anonymity of cryptocurrencies [32].

Table 3 provides an overview of categorized airport security risks and their associated MITRE techniques, listing all ten Initial Access techniques and one Impact technique

6. Airport Security Risks and MITRE ATT&CK Matrix This section provides a comprehensive analysis of

(retrieved September 2024). Each technique is identified and referenced by an ID (e.g., T1189, T1190).

the security risks faced by airports, categorizing these risks

6.3 MITRE Initial Access Techniques (TA0001)

in alignment with the MITRE ATT&CK Matrix for Enterprise

Initial Access is a critical phase in the cyber kill chain,

(or MITRE Matrix) [98]. This widely adopted cybersecurity

representing the methods adversaries use to gain entry into

knowledge base outlines the tactics, techniques and procedures

target systems. Below are the relevant techniques from

(TTPs) utilized globally for threat analysis and security defenses.

the MITRE Matrix associated with Initial Access and

Notably, this paper is the first to propose applying the MITRE

the corresponding airport security risks:

Matrix to bolster the cybersecurity posture of airports.

Public-facing Access (T1659, T1190, T1200): Techniques

We correlate all identified airport security risks—derived

such as Content Injection (T1659) allow attackers to insert

from cybersecurity incidents and a systematic literature

malicious content into network traffic, often through public Wi-Fi.

review—with MITRE techniques to mitigate cyberattacks

Exploiting vulnerabilities in public-facing applications (T1190),

MITRE Matrix Initial Access Tactic: https://attack.mitre.org/tactics/TA0001/

3

2

54 วารสารเทคโนโลยีีสารสนเทศ มจพ.

Information Technology Journal KMUTNB

MITRE Matrix Impact Tactic: https://attack.mitre.org/tactics/TA0040/

ปีี ที่่� 21 ฉบัับที่่� 2 กรกฎาคม - ธัันวาคม 2568 Vol. 21, No. 2, July - December 2025

Research Paper: Safeguarding Skies: Airport Cybersecurity in the Digital Age

Table 3. Summary of Airport Security Risks Linked to MITRE Matrix Tactics and Techniques. Impact: TA0040

Initial Access: TA0001

Airport Security Risk T1659

T1189

T1190

T1133

1. Public-facing Accesses

2. Insecure Network Architecture

3. Internet-facing Applications and Services

T1200

T1566

T1091

T1195

T1199

T1078

4. Social Engineering Attacks

5. Malware and Ransomware

6. Data Breach

7. Supply Chain and Third Party

T1498

8. Insider Threats

9. DoS

• •

The sign ● indicates that the airport security risk shown can be categorized according to the specific MITRE Matrix technique.

Associated MITRE Initial Access Tactic (TA0001)

ID

Technique

T1659 T1189 T1190 T1133 T1200 T1566 T1091 T1195 T1199 T1078

Content Injection Drive-by Compromise Exploit Public-Facing Application External Remote Services Hardware Additions Phishing Replication Through Removable Media Supply Chain Compromised Trusted Relationship Valid Accounts Associated MITRE Impact Tactic (TA0040)

ID

Technique

T1498

Network Denial of Service

Internet-facing Applications and Services (T1190, T1133): The presence of internet-facing applications and services exposes airports to significant cybersecurity risks via techniques such as Exploiting Public-facing Applications (T1190) and External Remote Services (T1133). Attackers can target vulnerabilities within publicly accessible systems—like online booking websites and service APIs—to gain unauthorized access to sensitive assets. Insecure remote services can also create entry points for attackers, allowing them to gain unauthorized access to internal systems through airport VPNs [100].

such as kiosks and charging stations, can provide unauthorized

Social Engineering (T1659, T1189, T1566, T1091, T1078):

access due to unpatched vulnerabilities or misconfigurations.

Techniques such as Content Injection (T1659), Drive-by

This may be coupled with Hardware Additions (T1200),

Compromise (T1189), and Phishing (T1566) are utilized to

where attackers exploit exposed ports to introduce unauthorized

manipulate victims. The use of insecure removable media

devices [99].

(T1091) may allow untrusted devices to introduce malware to

Insecure Network Architecture (T1659, T1190, T1133):

critical systems [101]. Technique like Valid Accounts

Techniques such as Content Injection (T1659) and Exploiting

(T1078) may enable attackers to gain access via stolen account.

Public-facing Applications (T1190) become more dangerous in

Malware, Ransomware and Data Breach (T1659,

poorly secured environments, allowing attackers to gain initial

T1189, T1190, T1133, T1200, T1566, T1091, T1195,

access and subsequently move laterally. Additionally, External

T1199, T1078): Malware, ransomware, and data breaches

Remote Services (T1133) may compromise internal network by

exploit various techniques within airport systems. Initial Access

enabling unauthorized access through insecure remote connections.

tactics, such as Content Injection (T1659) and Exploiting

ปีี ที่่� 21 ฉบัับที่่� 2 กรกฎาคม - ธัันวาคม 2568

Vol. 21, No. 2, July - December 2025

วารสารเทคโนโลยีีสารสนเทศ มจพ. 55

Information Technology Journal KMUTNB

Research Paper: Safeguarding Skies: Airport Cybersecurity in the Digital Age

Public-facing Applications (T1190) enable attackers to

7.1 Cybersecurity Frameworks and Requirements

infiltrate via public interfaces. Techniques like Drive-by

Numerous studies emphasize the important of adopting

Compromise (T1189), Phishing (T1566), and the use of

cybersecurity frameworks to enhance airport security [1], [5], [8],

insecure removable media (T1091) increase the risk of malware

[41], [55], [67], [68]. Frameworks, such as NIST Cybersecurity

and ransomware, ultimately leading to data breaches.

Framework, can help identify weaknesses and facilitate

External Remote Services (T1133) and Valid Accounts (T1078)

development of security objectives. The Civil Air Navigation

allow attackers to leverage stolen credentials to penetrate

Services Organization (CANSO) has proposed guidelines to

into the networks, facilitating ransomware and data theft.

elevate security levels through these frameworks [102], and

Risks from Supply Chain Compromise (T1195) and Trusted

several airports, including Airports of Thailand, have already

Relationship (T1199) may introduce vulnerabilities into

implemented such policies [103].

overall security.

Recently, the TSA issued new cybersecurity requirements,

Supply Chain and Third Party (T1195, T1199): With

mandating all U.S. airports and aircraft operators to develop

multiple party involved, techniques such as Supply Chain

cybersecurity policies [104], [105]. Additionally, ICAO has

Compromise (T1195) and Trusted Relationship (T1199)

created Standards and Recommended Practices [106], [107]

presents significant threat to airports, allowing attackers to

that urge airports to implement cybersecurity risk management

exploit vulnerabilities without raising immediate suspicion.

frameworks and collaborate to advance ICAO's cybersecurity

Insider Threat (T1091, T1199, T1078): Techniques

framework.

such as Insecure Removable Media (T1091) can enable

7.2 Zero Trust Architecture

employees to introduce malware into the system.

Zero Trust is a modern cybersecurity framework that

Exploitation of Trusted Relationships (T1199) may allow

prioritizes verifying and protecting all entities based on

insiders to manipulate external connections, leading to

the principle of least privilege. It involves capturing and

unauthorized sharing of sensitive information. Additionally,

analyzing logs for effective threat response, acknowledging

Valid Accounts (T1078) could allow insiders to misuse their

that internal threats may stem from untrusted devices and

credentials.

personnel. The following discussion highlights the benefits

6.4 MITRE Impact (TA0040) for Denial-of-Service

of implementing Zero Trust architecture in airport security.

Denial-of-Service (T1498): According to the MITRE

Visibility for Subsystems. The initial phase of

framework, DoS attacks fall under the Impact tactic, specifically

an integrated Zero Trust architecture involves identifying

technique ID T1498. This can be executed through methods

organizational assets, their value, stakeholders, and connectivity.

such as direct network floods (T1498.001) or reflection

This foundational step prioritizes Zero Trust security policies,

amplification (T1498.002).

including secure access, the principle of least privilege, and enhanced visibility into subsystems.

7. Modern Defenses for Airport Security

Network Segmentation. Network segmentation is

In this section, we outline modern security defense strategies

a foundational element of the Zero Trust architecture, allowing

and best practices specifically designed for airport.

network administrators to enforce the principle of least privilege.

The key focus areas include the adoption of Cybersecurity

For instance, the IoT network is isolated from other segments to

Frameworks and the implementation of Zero Trust Architecture,

prevent unauthorized parties from exploiting IoT vulnerabilities

along with additional defenses addressing the identified risks

and mitigate the risk of lateral movement within the airport's

in previous sections.

infrastructure.

56 วารสารเทคโนโลยีีสารสนเทศ มจพ.

Information Technology Journal KMUTNB

ปีี ที่่� 21 ฉบัับที่่� 2 กรกฎาคม - ธัันวาคม 2568 Vol. 21, No. 2, July - December 2025

Research Paper: Safeguarding Skies: Airport Cybersecurity in the Digital Age

Demilitarized Zone. Internet-based services are prime

encompass regular off-site data backups. These backups

targets for cyberattacks, making it essential to configure

must be secured against common threats, such as ransomware

a separate network segment called a "Demilitarized Zone" (DMZ).

that seeks to compromise backup files (T1486) [109].

The DMZ acts as a controlled gateway between the internal

Routine testing of backup restoration procedures is crucial to

network and the internet, enforcing strict connectivity rules

ensure their usability in the event of an incident.

through firewalls and packet filtering.

Data Breach Prevention involves proactive monitoring

The External Policy Enforcement Point (PEP) in Figure 2

of data for irregular patterns—such as unexpected changes in

filters malicious internet traffic, while the Internal PEP manages

data size, unusual timestamps, or unauthorized access

the traffic between DMZ servers and the internal network.

attempts—is essential for early detection of potential breaches.

This layered security approach ensures that external services

Strong authentication and encryption for data access further

remain isolated from internal systems.

safeguard sensitive information from unauthorized users

7.3 Security Awareness Training. The aviation sector may soon face regulatory mandates requiring security

and ensure compliance with relevant regulatory data security and privacy requirements.

awareness training for employees [4], [7]. To effectively

7.5 Supply Chain and Third Party Risk Management

implement such programs, organizations actively engage in

Due Diligence in Supply Chain Management.

the development process, providing continuous feedback to

Any third-party solutions integrated into airport systems

enhance the training effectiveness.

must be treated as part of the airport's threat landscape. A rigorous selection process should assess adaptability, security features, secure update mechanisms, and support systems to effectively manage security liabilities and reduce the risk of unforeseen incidents. Physical Access Restrictions and Tamper Proofing. IoT devices deployed throughout airports are susceptible to

Figure 2. DMZ subnet that separates an enterprise internal network from other untrusted networks e.g., the Internet.

physical access attacks, where criminals may steal them for unauthorized entry. To mitigate this risk, various tamper-proof techniques can be applied [110], [111]. For instance, devices

7.4 Malware, Ransomware and Data Breach

can be housed in secure or tamper-resistant cases and

In addition to previously discussed security measures,

disabling or factory resetting.

airports should implement targeted strategies to detect malware

7.6 Insider Threat Mitigation

and ransomware. The following mitigation strategies can

Mitigating insider threats is challenging, as they often

strengthen an airport's cybersecurity posture:

bypass traditional security measures. Prevention relies on

Endpoint Detection and Response (EDR). To bolster

the principle of least privilege, restricting user access to

cybersecurity, airports should implement advanced anomaly

essential functions, along with monitoring for anomalous

detection and monitoring to swiftly identify unusual patterns

behaviors. Implementing a Zero Trust Architecture strengthens

indicative of ransomware. EDR solutions provide real-time

security by requiring identity verification for every access

analysis of host activities, enabling rapid detection of malicious

request and ensuring all access is logged and analyzed.

behaviors [108].

7.7 Denial-of-Service Mitigation

Data Backup and Disaster Recovery. It is imperative to

Cloud or Hybrid DoS Scrubbing Platforms enhance

implement comprehensive IT disaster recovery plans that

security by redirecting traffic through specialized infrastructure

ปีี ที่่� 21 ฉบัับที่่� 2 กรกฎาคม - ธัันวาคม 2568

Vol. 21, No. 2, July - December 2025

วารสารเทคโนโลยีีสารสนเทศ มจพ. 57

Information Technology Journal KMUTNB

Research Paper: Safeguarding Skies: Airport Cybersecurity in the Digital Age

that filters out malicious traffic before it reaches the airport's

Generative AI, focusing on their effectiveness in enhancing

network [112], [113]. Incorporating redundancy and failover

airport operations while mitigating potential vulnerabilities.

mechanisms is also essential, as it improves resilience and

While existing studies have started to address these gaps,

minimizes downtime, ensuring essential services remain

ongoing research is essential to keep up with emerging

operational during an attack.

threats and solutions.

7.8 Collaborative Threat Intelligence Sharing Numerous studies underscore the importance of information

9. Conclusion

sharing within the industry [5], [61], [64], [114]. A real-world

This paper explores the critical area of airport cybersecurity,

example demonstrates the effectiveness: during a spear phishing

highlighting the seriousness of emerging threats in this domain.

campaign targeting airport executives, emails containing

Through insights gained from recent real-world incidents

malware were detected. Through collaborative efforts,

and a systematic literature review, we conducted a comprehensive

the attack was neutralized across the sector [115]. By adopting

analysis and categorized major cybersecurity risks confronting

a multi-faceted approach, including collaborative threat

airports, aligned with the MITRE ATT&CK Matrix, providing

intelligence sharing, airports can enhance their defenses

a valuable framework for exploring practical defenses and

against evolving cyber threats.

best practices articulated in the MITRE knowledge base. In conclusion, we advocate for the adoption of modern

8. Challenges and Future Research Directions

security policies, including robust Cybersecurity Frameworks

While a range of defenses have been detailed, significant

and Zero Trust Architecture, alongside critical security measures.

challenges remain that must be addressed in order to further

This study aims to enhance the aviation industry's understanding

enhance airport cybersecurity

of the current threat landscape and provide a foundation

Evolving Threat Landscape. Cyber threats are continuously

for enhancing cybersecurity defense and resilience.

evolving and becoming more sophisticated, and diversified. This necessitates ongoing research and airport adaptability to

10. References

counter new attack vectors.

[1]

G. Lykou, A. Anagnostopoulou, and D. Gritzalis.

Resource Constraints. Smaller airports often face significant

"Smart Airport Cybersecurity: Threat Mitigation

resource limitations e.g., budget and personnel, hindering

and Cyber Resilience Controls." Sensors, Vol. 19,

the implementation of cybersecurity measures.

No. 1, 2019.

Integration of Legacy Systems. Integrating modern

[2]

EUROCONTROL, Aviation under Attack from

security measures with outdated systems presents significant

a Wave of Cybercrime. Available Online at https://

challenges and often requires substantial investment.

www.eurocontrol.int/publication/eurocontrol-

Future Research Directions. Our literature review reveals

think-paper-12-aviation-under-attack-wave-cyber

a pressing need for further research in key areas: (1) Supply Chain

crime, accessed on 1 February 2024.

and Third-Party Risks, (2) Cybersecurity Awareness, and

[3]

Business Insurance, US to add cybersecurityrequirements

(3) Development of Airport-Specific Cybersecurity Frameworks.

for critical aviation systems. Available Online at

The limited publications in these domains highlight the unique

https://www.businessinsurance.com/article/20221012/

challenges airports face.

NEWS06/912353045/US-to-add-cybersecurity-re

Additionally, future research should investigate the integration

quirements-for-critical-aviation-systems, accessed on

of advanced technologies like Machine Learning, AI, and

1 February 2024.

58 วารสารเทคโนโลยีีสารสนเทศ มจพ.

Information Technology Journal KMUTNB

ปีี ที่่� 21 ฉบัับที่่� 2 กรกฎาคม - ธัันวาคม 2568 Vol. 21, No. 2, July - December 2025

Research Paper: Safeguarding Skies: Airport Cybersecurity in the Digital Age

[4]

IATA, Compilation of Cyber Security Regulations,

https://www.bloomberg.com/news/articles/2021-06-04/

Standards, and Guidance Applicable to Civil Aviation

hackers-breached-colonial-pipeline-using-com

Edition 3.0. Available Online at https://www.iata.org/

promised-password, accessed on 1 February 2024.

c o n t e n t a s s e t s / 4 c 5 1 b 0 0 f b 2 5 e 4 b 6 0 b

[13]

CNN, Ransomware attack hits New Jersey county.

38376a935e278b/compilation-of-cyber-regulations-

Available Online at https://www.cnn.com/2022/05/26/

standards-and-guidance3.0.pdf, accessed on

politics/new-jersey-somerset-county-ransomware-

1 February 2024.

attack, accessed on 1August 2023.

[5]

N. Koroniotis, N. Moustafa, F. Schiliro, P. Gauravaram,

[14]

Threatpost, N.J.'s Largest Hospital System Pays Up

and H. Janicke. "A Holistic Review of Cybersecurity

in Ransomware Attack. Available Online at https://

and Reliability Perspectives in Smart Airports."

threatpost.com/ransomware-attack-new-jersey,

IEEE Access, Vol. 8, pp. 209802-209834, 2020.

accessed on 1 February 2024.

[6]

A. Fattah, H. Lock, W. Buller, and S. Kirby. Smart

[15]

Mandiant, Advanced Persistent Threats (APTs) --

Airports: Transforming Passenger Experience to

Threat Actors & Groups. Available Online at

Thrive in the New Economy. Available Online at

https://www.mandiant. com/resources/insights/apt-

https://www.cisco.com/c/dam/en_us/about/ac79/

groupsm, accessed on 1 June 2023.

docs/pov/Passenger_Exp_POV_0720aFINAL.pdf,

[16]

ZDNET, Russian state hackers behind San Francisco

accessed on 1 February 2024.

Airport Hack. Available Online at https://www.zdnet.

[7]

TSA, 20 years after 9/11: The state of the transportation

com/article/russian-state-hackers-behind-san-fran

security administration. Available Online at https://

cisco-airport-hack/, accessed on 1 February 2024.

shorturl.at/1lsGo, accessed on 1 February 2024.

[17]

Security Affairs, A Cyber Attack Hit The Beirut

[8]

G. Lykou, A. Anagnostopoulou, and D. Gritzalis.

International Airport. Available Online at https://

"Implementing Cyber Security Measures in Airports to

securityaffairs.com/157079/hacking/cyber-attack-

Improve Cyber Resilience." Proceedings of the 2018

hit-beirut-international-airport.html, accessed on

Global Internet of Things Summit, pp. 1-6, 2018.

1 February 2024.

[9]

J. H. Tan and T. Masood. "Adoption of Industry 4.0

[18]

Homeland Security Today, Long Beach Airport’s

Technologies in Airports - A Systematic Literature

Website Taken Down By Cyber Attack. Available

Review." ArXiv, pp. 1-25, 2021.

Online at https://www.hstoday.us/subject-matter-areas/

[10]

M. Javaid, A. Haleem, R. P. Singh, R. Suman, and

transportation/long-beach-airports-website-taken-

E. S. Gonzalez. "Understanding the Adoption of

down-by-cyber-attack/, accessed on 1 June 2023.

Industry 4.0 Technologies in Improving Environmental

[19]

The Record, Major Mexican airport confirms experts

Sustainability." Sustainable Operations and Computers,

are working to address cyberattack. Available Online at

Vol. 3, pp. 203 - 217, 2022.

https://therecord.media/queretaro-international-airport-

[11]

K. Gopalakrishnan, M. Govindarasu, D. Jacobson,

mexico-cyberattack, accessed on 1 February 2024.

and B. M. Phares. "Cyber Security for Airports."

[20]

NTV, KAA confirms data breach, says no sensitive

International Journal for Traffic and Transport

data leaked. Available Online at https://ntvkenya.

Engineering (IJTTE), Vol. 3, No. 4, pp. 365-376, 2013.

co.ke/news/kaa-confirms-data-breach-says-no-

[12]

Bloomberg, Colonial Pipeline Cyber Attack: Hackers

sensitive-data-leaked/, accessed on 1 May 2023.

Used Compromised Password. Available Online at

[21]

Airport Technology, Ransomware attack on Swissport

ปีี ที่่� 21 ฉบัับที่่� 2 กรกฎาคม - ธัันวาคม 2568

Vol. 21, No. 2, July - December 2025

วารสารเทคโนโลยีีสารสนเทศ มจพ. 59

Information Technology Journal KMUTNB

Research Paper: Safeguarding Skies: Airport Cybersecurity in the Digital Age

causes delay at Zurich Airport. Available Online at

knock US airport websites offline. Available Online at

https://www.airport-technology.com/news/ransomware-

https://apnews.com/article/technology-business-

attack-swissport-zurich-airport/, accessed on

atlanta-680cf93f7eb0300127448c35299ad66e,

1 February 2024.

accessed on 1 February 2024.

[22]

Security Affairs, A Cyber Attack Hit The Beirut

[30]

Euractiv, Italy target of major Russia-linked cyberattack,

International Airport. Available Online at https://

again. Available Online at https://shorturl.at/Kvn9C,

securityaffairs.com/157079/hacking/cyber-attack-

accessed on 1 February 2024.

hit-beirut-international-airport.html, accessed on

[31]

CyberMaterial, Cyberattack Hit Copenhagen Airport.

1 February 2024.

Available Online at https://cybermaterial.com/

[23]

The Cyber Express, DDoS Cyberattack Hits Cairo

cyberattack-hit-copenhagen-airport/, accessed on

International Airport: Anonymous Collective Claims

1 February 2024.

Responsibility. Available Online at https://thecyberexpress.

[32]

The Wall Street Journal, Why Hackers Use Bitcoin

com/cairo-international-airport-cyberattack, accessed on

and Why It Is So Difficult to Trace. Available Online

1 February 2024.

at https://www.wsj.com/articles/why-hackers-use-

[24]

Czech Police, Interior Ministry, Airport Websites

bitcoin-and-why-it-is-so-difficult-to-trace-

Come Under Cyber Attack. Available Online at

11594931595, accessed on 1 February 2024.

https://brnodaily.com/2023/10/24/news/czech-

[33]

SecurityWeek, Data Stolen in Ransomware Attack That

police-interior-ministry-airport-websites-come-under-

Hit Seattle Airport. Available Online at https://www.

cyber-attack/, accessed on 1 February 2024.

securityweek.com/data-stolen-in-ransomware-attack-

[25]

The Record, Canada blames border checkpoint

that-hit-seattle-airport, accessed on 1 February 2024.

outages on cyberattack. Available Online at https://

[34]

Halcyon Tech, Monti Ransomware Attack on Ae ́ŕ oport

therecord.media/canada-border-checkpoint-outages-

de Pau. Available Online at https://ransomwareattacks.

ddos-attack-russia, accessed on 1 May 2023.

halcyon.ai/attacks/monti-ransomware-attack-on-

[26]

Tech Monitor, Charles de Gaulle Airport website

aeroport-de-pau, accessed on 1 February 2024.

offline after suspected '#OpFrance' DDoS cyberattack.

[35]

BARRON'S, Cyberattack Hits Croatia’s Split Airport.

Available Online at https://techmonitor.ai/technology/

Available Online at https://www.barrons.com/

cybersecurity/opfrance-cyberattack-charles-de-gaulle-

news/cyberattack-hits-croatia-s-split-airport-

airport, accessed on 1 June 2023.

dac3d776, accessed on 1 February 2024.

[27]

Mirror, UK airports targeted by coordinated Russia

[36]

HACKREAD, Hackers Leak 2.5M Private Plane

cyberattack groups. Available Online at https://

Owners' Data Linked to LA Intl. Airport Breach.

www.mirror.co.uk/travel/news/uk-airports-targeted-

Available Online at https://hackread.com/hackers-leak-

coordinated-russia-30504938, accessed on

private-plane-owners-data-la-airport-breach/,

1 February 2024.

accessed on 1 August 2024.

[28]

Information Week, The DDoS Attack on German

[37]

AP, Hacked Brazil Airport Screens Show Porn

Airport Websites and What IT Leaders Can Learn.

to Travelers. Available Online at https://apnews.

Available Online at https://shorturl.at/7ACXL,

com/article/entertainment-caribbean-brazil-

accessed on 1 February 2024.

c0842e915c403c41830 6433cdfc406a6, accessed on

[29]

The Associated Press, Denial-of-service attacks

1 February 2024.

60 วารสารเทคโนโลยีีสารสนเทศ มจพ.

Information Technology Journal KMUTNB

ปีี ที่่� 21 ฉบัับที่่� 2 กรกฎาคม - ธัันวาคม 2568 Vol. 21, No. 2, July - December 2025

Research Paper: Safeguarding Skies: Airport Cybersecurity in the Digital Age

[38]

KTSM.com, FBI warns cyber criminals are spoofing

2021 IEEE 11th Annual Computing and Communication

airport websites and Wi-Fi. Available Online at

Workshop and Conference (CCWC), NV, USA,

https://shorturl.at/vJRE7, accessed on 1 February 2024.

pp. 565-571, 2021.

[39]

The New York Times, Stranded in the CrowdStrike

[47]

J. Haan. "Specific Air Traffic Management Cybersecurity

Meltdown: 'No Hotel, No Food, No Assistance'.

Challenges: Architecture and Supply Chain."

Available Online at https://www.nytimes.com/

ICSEW'20: Proceedings of the IEEE/ACM 42nd

2024/09/13/travel/crowdstrike-outage-delta-airlines.

html, accessed on 1 February 2024.

Workshops, New York, NY, USA, pp. 245-249, 2020.

[40]

BCC, Scam warning as fake emails and websites

[48]

C. Aranzazu-Suescun, L. F. Zapata-Rivera,

target users after outage. BBC. Available Online at

O. G.-M. Saenz, and J. M. Christensen. "Securing

https://www.bbc.com/news/articles/cq5xy12pynyo,

IoT Surveillance Airport Infrastructure."

accessed on 1 February 2024.

Proceedings of the 2024 International Conference

[41]

G. Dave, G. Choudhary, V. Sihag, I. You, and

K.-K. R. Choo. "Cyber Security Challenges in Aviation

Networking, Harrisonburg, VA, USA, pp. 1-7, 2024.

Communication, Navigation, and Surveillance."

[49]

E. Pik. "Airport Security: The Impact of AI on Safety,

Computers & Security, Vol. 112, 2022.

Efficiency, and the Passenger Experience."

[42]

E. Andreev and D. Dimitrov. "Analysis of Cyber

Journal of Transportation Security, Vol. 17, No. 1,

Vulnerabilities in Civil Aviation and Recommendations

December, 2024.

for Their Mitigation." Aeronautical Research and

[50]

D. Shevchuk and I. Steniakin. "A Holistic Approach to

Development, Vol. 1, pp. 90-99, 2022.

Ensuring Safety and Cybersecurity in the Use of

[43]

A. Elmarady and K. Rahouma. "Studying Cybersecurity

Intelligent Technologies in Air Transport."

in Civil Aviation, including Developing and Applying

Electronics and Control Systems, Vol. 1, No. 75,

Aviation Cybersecurity Risk Assessment." IEEE Access,

pp. 97-101, 2023.

Vol. 4, 2016.

[51]

The Wall Street Journal, Pager Attacks in Lebanon

[44]

M. L. Salgado and M. S. de Sousa. "Cybersecurity

'Weaponize' Supply Chains. Available Online at

in Aviation: The STPASEC Method Applied to

https://www.wsj.com/articles/pager-attacks-in-lebanon-

the TCAS Security." 2021 10 th Latin-American

weaponize-supply-chains-60722390, accessed on

Symposium on Dependable Computing (LADC),

1 February 2024.

Florianópolis, Brazil, pp. 1-10, 2021.

[52]

R. Sabillon and J.R.B. Higuera. "The Importance of

[45]

S. Khandker, H. Turtiainen, A. Costin, and T. Hämäläinen.

Cybersecurity Awareness Training in the Aviation

"Cybersecurity Attacks on Software Logic and Error

Industry for Early Detection of Cyberthreats and

Handling within ADS-B Implementations: Systematic

Vulnerabilities." International Conference on Human-

Testing of Resilience and Countermeasures." IEEE

Computer Interaction, pp. 461-479, 2023.

Transactions on Aerospace and Electronic Systems,

[53]

S. Chockalingam, E. Nystad, and C. Esnoul.

Vol. 58, No. 4, pp. 2702-2719, 2022.

"Capability Maturity Models for Targeted Cyber

[46]

A. A. Alsulami and S. Zein-Sabatto. "Resilient Cyber-

Security Training." Proceedings of the International

security Approach for Aviation Cyber-physical

Conference on Human-Computer Interaction,

Systems Protection against Sensor Spoofing Attacks."

pp. 576-590, 2023.

ปีี ที่่� 21 ฉบัับที่่� 2 กรกฎาคม - ธัันวาคม 2568

Vol. 21, No. 2, July - December 2025

International Conference on Software Engineering

on Smart Applications, Communications and

วารสารเทคโนโลยีีสารสนเทศ มจพ. 61

Information Technology Journal KMUTNB

Research Paper: Safeguarding Skies: Airport Cybersecurity in the Digital Age

[54]

The Hacker News, Why Human Error is #1 Cyber

Security Threat to Businesses in 2021. Available

Journal, Vol. 4, No. 3, pp. 267-291, 2021.

Online at https://thehackernews.com/2021/02/

[63]

M. Karpiuk and M. Kelemen. "Cybersecurity in

why-human-error-is-1-cyber-security.html, accessed on

Civil Aviation in Poland and Slovakia." Cybersecurity

1 February 2024.

and Law, Vol. 8, No. 2, pp. 70-83, 2022.

[55]

P. Stastny and A. M. Stoica. "Protecting Aviation

[64]

C. Nobles, D. Burrell, and T. Waller. "The Need for

Safety Against Cybersecurity Threats." IOP Conference

a Global Aviation Cybersecurity Defense Policy"

Series: Materials Science and Engineering, Vol. 1226,

Land Forces Academy Review, Vol. 27, No. 1,

No. 1, pp. 12-25, 2022.

pp. 19-26, March 2022.

[56]

H. Saada, R. Orizio, and S. Sebastio. "Modeling

[65]

V. Filinovych and Z. Hu. "Aviation and the Cybersecurity

and Conducting Security Risk Assessment of Smart

Threats." Proceedings of the International Conference

Airport Infrastructures with SECRAM." Proceedings of

on Business, Accounting, Management, Banking,

the 7th International Conference on Networking,

Economic Security and Legal Regulation Research

Intelligent Systems and Security, No. 59, pp. 1-7, 2024.

(BAMBEL 2021), pp. 120-126, 2021.

[57]

T. Jeeradist. "Flight Delays and Cancellations Due to

[66]

M. Klenka. "Aviation Cyber Security: Legal Aspects

Airport Technology Network Disruptions Worldwide."

of Cyber Threats." Journal of Transportation Security,

KBU Journal of Aviation Management: KBUJAM,

Vol. 14, No. 3, pp. 177-195, December, 2021.

Vol. 2, No. 1, pp. 51-60, 2024.

[67]

S. Adhikari and S. Mirchandani. "Integrating Risk

[58]

L. Florido-Benítez. "The Types of Hackers and

Assessment Modeling with Aviation Cybersecurity

Cyberattacks in the Aviation Industry." Journal of

Framework." AIAA AVIATION 2020 FORUM,

Transportation Security, Vol. 17, No. 13, 2024.

pp. 29-32, 2020.

[59]

H. Su and W. Pan. "Using Digital Twins to Integrate

[68]

S. Adhikari. "An Analysis of AIAA Aviation

Cyber Security with Physical Security at Smart

Cybersecurity Framework in Relation to NIST,

Airports." Interdisciplinary Journal of Engineering

COBIT and DHS Frameworks." AIAA AVIATION

and Environmental Sciences, Vol. 10, No. 1,

2020 FORUM, pp. 2930, 2020.

pp. 38-45, January-March, 2023.

[69]

B. Kotkova. "Information Systems and Technologies

[60]

S. Samuri, M.F.A. Khir, Z.M. Amin, and M. F. N.

for the Safe Operation of Airports." Proceedings of

Mohammad. "Cybersecurity Maturity Framework

the 26th International Conference on Circuits, Systems,

for International Airports in Malaysia: A Systematic

Communications and Computers, IEEE, pp. 161-166,

Literature Review (SLR)." Journal of Information

2022.

and Knowledge Management (JIKM), Vol. 2,

[70]

R. A. Ramadan, B. W. Aboshosha, J. S. Alshudukhi,

pp. 156-167, 2023.

A. J. Alzahrani, A. El-Sayed, and M. M. Dessouky.

[61]

E. Ukwandu, M. Ben-Farah, H. Hindy, M. Bures,

"Cybersecurity and Countermeasures at the Time

R. Atkinson, C. Tachtatzis, I. Andonovid, and

of Pandemic." Journal of Advanced Transportation,

X. Bellekens. "Cybersecurity Challenges in Aviation

Vol. 2021, No. 1, 2021.

Industry: A Review of Current and Future Trends."

[71]

Trend Micro, The case for making BYOD safe-

Information, Vol. 13, No. 3, 2022.

security news. Available Online at https://www.

[62]

trendmicro.com/vinfo/us/security/news/internet-

L.F. Benítez. "Identifying Cyber Security Risks in

62 วารสารเทคโนโลยีีสารสนเทศ มจพ.

Information Technology Journal KMUTNB

Spanish Airports." Cyber Security: A Peer-Reviewed

ปีี ที่่� 21 ฉบัับที่่� 2 กรกฎาคม - ธัันวาคม 2568 Vol. 21, No. 2, July - December 2025

Research Paper: Safeguarding Skies: Airport Cybersecurity in the Digital Age

of-things/the-case-for-making-byod-safe, accessed on

[80]

S. Sivakorn, A. D. Keromytis, and J. Polakis.

1 February 2024.

"That's the Way the Cookie Crumbles: Evaluating

[72]

C. Brook, The Ultimate Guide to BYOD Security:

HTTPS Enforcing Mechanisms." Proceedings of

Definition & More. Available Online at https://

the 2016 ACM on Workshop on Privacy in the

digitalguardian.com/blog/ultimate-guide-byod-security-

Electronic Society, 2016.

overcoming-challenges-creating-effective-policies-

[81]

S. Sivakorn, P. Sirawongphatsara, and N. Rujiratanapat.

and-mitigating, accessed on 1 June 2023

"Web Encryption Analysis of Internet Banking

[73]

A. Bridgwater, How mobile device management is

Websites in Thailand." Proceedings of the 17th

taking on the BYOD challenge. Available Online at

International Joint Conference on Computer Science

https://www.theregister.com/2014/11/08/mobile

and Software Engineering, pp. 139-144, 2020.

working/, accessed on 1 June 2023.

[82]

M. Kacic, P. Hanacek, M. Henzl, and P. Jurnecka.

[74]

Y. Joshi, D. Das, and S. Saha. "Mitigating Man in

"Malware Injection in Wireless Networks."

the Middle Attack Over Secure Sockets Layer."

Proceedings of the 7th International Conference on

Proceedings of the 2009 IEEE International Conference

on Internet Multimedia Services Architecture and

Systems, Vol. 01, pp. 483-487. 2013.

Applications (IMSAA), pp. 1-5, 2009.

[83]

A. Zimba, Z. Wang, and M. Mulenga. "Cryptojacking

[75]

M. Marlinspike, New Tricks for Defeating SSL in

Injection: A Paradigm Shift to Cryptocurrency-based

Practice. Black Hat USA, Available Online at

Web-centric Internet Attacks." Journal of Organizational

https://www.blackhat.com/presentations/bh-dc-09/

Computing and Electronic Commerce, Vol. 29,

Marlinspike/BlackHat-DC-09-Marlinspike-

pp. 40-59, 2019.

Defeating-SSL.pdf, accessed on 1 June 2023.

[84]

J. Spaulding, A. Krauss, and A. Srinivasan.

[76]

Norton, Public Wi-Fi: An Ultimate Guide on the

"Exploring an Open WiFi Detection Vulnerability as

Risks + How to Stay Safe. Available Online at

a Malware Attack Vector on iOS Devices."

Intelligent Data Acquisition and Advanced Computing

https://us.norton.com/blog/privacy/public-wifi,

Proceedings of the 7th International Conference on

accessed on 1 February 2024.

Malicious and Unwanted Software, pp. 87-93, 2012.

[77]

S. Englehardt, D. Reisman, C. Eubank, et al.

[85]

Krebson Security, Why is 'Juice Jacking' Suddenly

"Cookies that Give You Away: The Surveillance

Back in the News?. Available Online at https://

Implications of Web Tracking." Proceedings of the 24th

krebsonsecurity.com/2023/04/why-is-juice-jacking-

International Conference on World Wide Web,

suddenly-back-in-the-news/, accessed on 1 February 2024.

Florence, Italy, pp. 289-299, 2015.

[86]

Kaspersky, What is an Evil Twin Attack? Evil Twin

[78]

X. Zheng, J. Jiang, J. Liang, et al. "Cookies Lack

Wi-Fi Explained. Available Online at https://www.

Integrity: Real-World Implications." Proceedings of

kaspersky.com/resource-center/preemptive-safety/

the 24th USENIX Security Symposium, Washington, D.C,

evil-twin-attacks, accessed on 1 February 2024.

pp. 707-721, 2015.

[87]

V. Roth, W. Polak, E. G. Rieffel, and T. Turner.

[79]

S. Sivakorn, I. Polakis, and A. D. Keromytis.

"Simple and Effective Defense Against Evil Twin

"The Cracked Cookie Jar: HTTPS Cookie Hijacking

Access Points." Wireless Network Security,

and the Exposure of Private Information."

pp. 220-235, 2008.

Proceedings of the 2016 IEEE Symposium on Security

[88]

H. Gonzales, K. Bauer, J. Lindqvist, D. McCoy,

and D. Sicker. "Practical Defenses for Evil Twin

and Privacy, pp. 724-742, 2016.

ปีี ที่่� 21 ฉบัับที่่� 2 กรกฎาคม - ธัันวาคม 2568

Vol. 21, No. 2, July - December 2025

วารสารเทคโนโลยีีสารสนเทศ มจพ. 63

Information Technology Journal KMUTNB

Research Paper: Safeguarding Skies: Airport Cybersecurity in the Digital Age

Attacks in 802.11." Proceedings of the 2010 IEEE Global

[99]

SecureList, DarkVishnya: Banks attacked through

Telecommunications Conference GLOBECOM 2010,

direct connection to local network. Available Online at

pp. 1-6, 2010.

https://securelist.com/darkvishnya/89169/,

[89]

Palo Alto Networks, What Is Network Segmentation?.

accessed on 1 February 2024.

Available Online at https://shorturl.at/rCIDK,

[100]

SecureWorks, Gold Sahara. Available Online at

accessed on 1 June 2023.

https://www.secureworks.com/research/threat-profiles/

[90]

The Local Austria, Turkish suspect identified in Vienna

gold-sahara, accessed on 1 February 2024.

airport cyberattack. Available Online at https://

[101]

Google, Turla: A Galaxy of Opportunity. Available

www.thelocal.at/20170228/suspect-identified-in-vienna,

Online at https://cloud.google.com/blog/topics/threat-

accessed on 1 June 2023

intelligence/turla-galaxy-opportunity, accessed on

[91]

H. Abbas, N. Emmanuel, M. F. Amjad, et al.

1 February 2024.

"Security Assessment and Evaluation of VPNs:

[102]

CANSO, CANSO Standard of Excellence in Cybersecurity.

A Comprehensive Survey." ACM Computing Surveys,

Available Online at https://canso.org/publication/

Vol. 55, No. 13s, pp.1-47, 2023.

canso-standard-of-excellence-in-cybersecurity/,

[92]

CISA, 2021 Top Routinely Exploited Vulnerabilities.

accessed on 1 February 2024.

Available Online at https://www.cisa.gov/news-

[103]

Airports of Thailand (AOT), AOT ICT Security Policy,

events/cybersecurity-advisories/aa22-117a,

AOT Cyber Security Policy and AOT Personal

accessed on 1 June 2023.

Data Protection Policy. Available Online at https://

[93]

TechTarget, The Mirai IoT Botnet holds strong in 2020.

corporate.airportthai.co.th/th/cybersecurity-th/,

Available Online at https://shorturl.at/GMUA8,

accessed on 1 February 2024.

accessed on 1 June 2023.

[104]

TSA, TSA issues new cybersecurity requirements

[94]

Keyfactor, Top 10 IoT Vulnerabilities in Your Devices.

for airport and aircraft operators. Available Online at

Available Online at https://www.keyfactor.com/

https://shorturl.at/eXlvZ, accessed on 1 June 2023.

blog/top-10-iot-vulnerabilities, accessed on 1 June 2023.

[105]

T. Szuba. Safeguarding Your Technology: Practical

[95]

Bloomberg, China Used a Tiny Chip in a Hack

Guidelines for Electronic Education Information

That Infiltrated U.S. Companies. Available Online at

Security. National Center for Education Statistics, 1998.

https://shorturl.at/tMHdW, accessed on 1 February 2024.

[106]

ICAO, Annex 17 - Aviation Security, ICAO - International

[96]

WIRED, Hacker Lexicon: What Is a Supply Chain

Standards and Recommended Practices. Available

Attack?. Available Online at https://www.wired.

Online at https://shorturl.at/JQHkr, accessed on

com/story/hacker-lexicon-what-is-a-supply-chain-

1 February 2024.

attack/, accessed on 1 June 2023.

[107]

ICAO, AVIATION CYBERSECURITY. (2022),

[97]

M. Theoharidou, S. Kokolakis, M. Karyda, and

Available Online at https://www.icao.int/aviation

E. A. Kiountouzis. "The insider threat to information

cybersecurity/Pages/default.aspx, accessed on

systems and the effectiveness of ISO17799."

1 February 2024.

Computers & Security, Vol. 24, pp. 472-484, 2005.

[108]

S.-J. Lee, H.Y. Shim, Y.R. Lee, T.R. Park, S.H. Park,

[98]

MITRE. MITRE ATT&ACK Matrix for Enterprise.

and I.G. Lee. "Study on Systematic Ransomware

Available Online at https://attack.mitre.org/,

Detection Techniques." Proceedings of the 24th

accessed on 1 September 2024.

International Conference on Advanced Communication

Technology (ICACT), pp. 297-301. 2022

64 วารสารเทคโนโลยีีสารสนเทศ มจพ.

Information Technology Journal KMUTNB

ปีี ที่่� 21 ฉบัับที่่� 2 กรกฎาคม - ธัันวาคม 2568 Vol. 21, No. 2, July - December 2025

Research Paper: Safeguarding Skies: Airport Cybersecurity in the Digital Age

[109]

MITRE, MITRE ATT&CK Matrix - Data Encrypted

org/techniques/T1498/, accessed on 1 February 2024.

for Impact. Available Online at https://attack.mitre.

[113]

WIRED, GitHub Survived the Biggest DDoS Attack

org/techniques/T1486/, accessed on 1 February 2024.

Ever Recorded. Available Online at https://www.

[110]

J. Katz. "Universally Composable Multi-party

wired.com/story/github-ddos-memcached/,

Computation using Tamper-proof Hardware."

accessed on 1 February 2024.

Advances in Cryptology – EUROCRYPT 2007,

[114]

I. A. Shah, N. Jhanjhi, and S. Brohi. "Cybersecurity

pp. 115-128, 2007.

Issues and Challenges in Civil Aviation Security."

[111]

R. Gennaro, A. Lysyanskaya, T. Malkin, S. Micali,

Cybersecurity in the Transportation Industry,

and T. Rabin. "Algorithmic Tamper-proof (ATP)

pp. 1-23, 2024.

Security: Theoretical Foundations for Security

[115]

D. S. Turetsky, B. H. Nussbaum, and U. Tatar.

Against Hardware Tampering." Theory of Cryptography

Success Stories in Cybersecurity Information Sharing.

Conference TCC 2004, 2004.

The College of Emergency Preparedness, Homeland

[112]

MITRE, MITRE ATT&CK Matrix - Network Denial

Security and Cybersecurity University at Albany, 2020.

of Service. Available Online at https://attack.mitre.

ปีี ที่่� 21 ฉบัับที่่� 2 กรกฎาคม - ธัันวาคม 2568

Vol. 21, No. 2, July - December 2025

วารสารเทคโนโลยีีสารสนเทศ มจพ. 65

Information Technology Journal KMUTNB

Record · ID 138860 · SHA-256 bbc6cb05faddb871
Retrieved via Conceptio — every document is proof-bundled with source, license, and retrieval metadata.