© 2005 The MITRE Corporation. All rights reserved.
Requirements and Tradeoffs“Securing and Growing Aviation”
Amr ElSawyTom Berry
Greg Nelson
Center for Advanced Aviation System DevelopmentThe MITRE Corporation
ATC Maastricht Conference 2005
© 2005 The MITRE Corporation. All rights reserved.
The Events of 9/11 Changed the Aviation World
“What is new is the range, scale, and intensity of the threat”
– Kofi Anon, 2 Dec 2004, The Economist
© 2005 The MITRE Corporation. All rights reserved.
Working to Make Air Transportation More Secure
Prevent
React
Protect
© 2005 The MITRE Corporation. All rights reserved.
But Where Has That Left the Passenger?
Source: http://www.reviewjournal.com/lvrj_home/2004/Jan-13-Tue-2004/photos/airport.jpg
© 2005 The MITRE Corporation. All rights reserved.
Imbedding Security in Every Element of The System – Use Time
and Space
ATM
Pilots
Aircraft
Travel Services
Passengers
Airlines
Hotels, Ground Transport
Schedules, Delays, fares, market offers
Schedules, Delays, cancellations
Schedule, status
Status, Conditions, Fuel, etc.
Flight Data, Instructions
ETMS, ATC Software
OAG/CRS, marketing info
Type, status
Services Provided
status
Itineraries
© 2005 The MITRE Corporation. All rights reserved.
Aviation Security Must Serve the Traveling Public
• Complement, not dominate the experience
• Avoid Stove Pipes
• Manage Flows
• Use Space and Time
• Continuous Sensing
Photo credits: UL. http://www.the-human-race.com/images/environment/smokestacks.jpg, UR. ,LL. http://www.anvil-media.com/archives/070102/gallery.html, LR. www.crispata.com/sample/pages/smokestack_color_submit.html
© 2005 The MITRE Corporation. All rights reserved.
Active, Alert, Aware, Fast, Resilient, Responsive, Comprehensive ?
DOJ
DoD/Northcom
Intelligence
Community
General & Biz Aviation
Airlines
AirportsProfitable, manageable
travel
Freight Forwarders
Local Law Enforcement
TSAProtect transportation systems, ensure freedom of movement
for people and commerce
DHS CBP
DoT
FAA
DHS IA&IP
Manufacturers & Shippers
Aircraft Manufacturers
NTSB
Aviation Training Orgs
Travel agents & GDSs
Risk Assessment
Providers
CDC
DOS
Public/IndustryPublic/Industry
GovernmentGovernment
DHS S&T
NASA
Travelers
DHS EPR
© 2005 The MITRE Corporation. All rights reserved.
Limited Choice is Accompanied by Information Asymmetries
?? Hmm?Hmm?
© 2005 The MITRE Corporation. All rights reserved.
DOJ
DoD/Northcom
Intelligence
Community
Local Law Enforcement
TSA
DHS CBP
DoT
FAA
DHS IA&IP
NTSB
CDC
DOS
GovernmentGovernment
DHS S&T
NASA
DHS EPR
Traditional Systems and Organizations Limit Information Choice
General & Biz Aviation
Airlines
Airports
Freight Forwarders
Manufacturers & Shippers
Aircraft ManufacturersAviation
Training Orgs
Travel agents & GDSs
Risk Assessment
Providers
Public/IndustryPublic/Industry
Travelers
If we knew all of the connections, we could build a roadmap to a more secure transportation environment
© 2005 The MITRE Corporation. All rights reserved.
Richness vs. Reach
A very rich exchange of detailed information but
limited to a very few
VS.Alert Alert Level Level
YellowYellow
A very broad exchange of information but with little
detail or context
Traditional systems and structures require a tradeoff between…
© 2005 The MITRE Corporation. All rights reserved.
But there is another way…Connect
© 2005 The MITRE Corporation. All rights reserved.
It’s a Matter of Putting the …
© 2005 The MITRE Corporation. All rights reserved.
Imagine A World…
SwiftTravel.Com
Video File
© 2005 The MITRE Corporation. All rights reserved.
Behind the Scenes, the Security System Makes Flights More Secure
SwiftTravel.Com
Video File
© 2005 The MITRE Corporation. All rights reserved.
Architecture Principles for the “New System”
• Efficient Flow in all segments of system• Multi-layered security enclaves using space and time• Early detection and correlation of events• Increase automation decision aids• Avoid/protect single points of failure• Provide common inter-organization situational
awareness• Construct self-healing information/decision networks• Distributed/mobile command and control• Manage the “soft inside”
© 2005 The MITRE Corporation. All rights reserved.
Important Challenges
• Aligning policies, regulations and institutional relationships
• Distributed Training and Scenario Execution
• Privacy v. Anonymity
• Investment choices and timing to implement capabilities
• Asymmetric and Distributed Threats
© 2005 The MITRE Corporation. All rights reserved.
“Move Anyone or Anything, Anywhere,
Anytime, On Time
AND
Know Almost Anything about
Almost Everything in Almost Real Time”