<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Studies on the Disasters Criticality Assessment in Aviation Information Infrastructure</article-title>
      </title-group>
      <contrib-group>
        <aff id="aff0">
          <label>0</label>
          <institution>Kyiv College of Communication</institution>
          ,
          <addr-line>Kyiv</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>National Aviation University</institution>
          ,
          <addr-line>Kyiv</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>State Scientific and Research Institute of Cybersecurity Technologies and Information Protection</institution>
          ,
          <addr-line>Kyiv</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff3">
          <label>3</label>
          <institution>Yessenov University</institution>
          ,
          <addr-line>Aktau</addr-line>
          ,
          <country country="KZ">Kazakhstan</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>Information and communication technologies (ICT) implementation in various industries, on the one hand, increases the efficiency of different business processes and, on the other hand, generates new threats and vulnerabilities in ICT. Critical infrastructures (CI) need principal new effective methods and means for cybersecurity ensuring. In the situation with limited resources, CI objects defining and ranking is an important task. To rank objectively, CI objects should be assessed using some criteria. Previously, authors have proposed a FMECA-based method to assess importance level (disasters criticality) for state critical information infrastructure, which allows ranking and evaluating the importance of CI objects using both quantitative and qualitative parameters. This paper presents a complex experimental study of the proposed method using the aviation industry as an example. An experimental technique was introduced and using it, the adequacy of method response to changing input data was checked. It confirmed the possibility of disaster criticality and importance level assessment of critical aviation information systems related to various categories: information systems for air navigation services; on-board information systems for aircraft; information systems for airlines and airports.</p>
      </abstract>
      <kwd-group>
        <kwd>critical information infrastructure</kwd>
        <kwd>criticality</kwd>
        <kwd>risk</kwd>
        <kwd>disaster</kwd>
        <kwd>critical aviation information systems</kwd>
        <kwd>experimental study</kwd>
        <kwd>cybersecurity</kwd>
        <kwd>aviation</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>
        Information and communication technologies (ICT) rapid development has led to
significant and sometimes revolutionary changes in all spheres of people’s lives in
most states of the world. This has significantly increased the vulnerability of various
networks, systems and ICT objects and has made it difficult to ensure their protection
Copyright © 2020 for this paper by its authors. This volume and its papers are published under
the Creative Commons License Attribution 4.0 International (CC BY 4.0).
and security. All these factors have caused the world's leading states to pay significant
attention to the protection of critical facilities, systems and resources, as well as to the
identifying critical infrastructures (CI) [
        <xref ref-type="bibr" rid="ref1 ref2">1-2</xref>
        ], assessing their criticality level and
impact of possible functional interruptions (failures). However, today there is no
universal method that could be used to assess the criticality level of CI in different industries
using both quantitative and qualitative parameters.
2
      </p>
      <p>
        Related papers analysis and problem statement
Increasing concentration of means and resources for protecting CI of different types
necessitated the ranking of CI objects, the selection of the most important ones and
the emergence of the CI concept [
        <xref ref-type="bibr" rid="ref3 ref4">3-4</xref>
        ]. In order to protect the most important CII
objects, it is necessary to first identify these objects by certain criteria [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ] and then
determine the criticality (assess the importance) of the identified objects [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ].
Particular attention needs to be given to aviation, where, in accordance with the
guidance documents [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ], so-called critical aviation information systems (CAIS) need
to be identified and protected against various cyberthreats. In works [
        <xref ref-type="bibr" rid="ref10 ref8 ref9">8-10</xref>
        ] the
FMECA-based (Failure Mode, Effects and Criticality Analysis) approach for
assessing CII objects in different industries of CI was presented and studied. In
general, FMECA requires the identification of the following basic information: Item,
Function, Failure, Effect of Failure, Cause of Failure, Current Control fn the
Recommended Actions.
      </p>
      <p>
        In the study [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ] authors have proposed a FMECA-based method of assessing the
importance level of CII objects in aviation, which makes it possible to evaluate the
importance level and to rank the CAIS [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ]. This method uses the introduction of a
basic set of systems and corresponding sets of subsystems, components, functions,
violations of continuity of work (interruption of work, loss of functionality), their
features and consequences, as well as the construction of a three-dimensional
criticality matrix.
      </p>
      <p>The main results of the implementation of the proposed method are presented in
the form of a report, which summarizes such information as: a list of system
components, their functions, types of interruptions for each component of the system;
information on the causes and consequences of interruptions for each component of
the system; calculations of criticality rankings, ranking results are a list of the most
significant (critical) interruptions of work, which are displayed in a formalized and
convenient for experts form. Other output data was obtained at different stages of the
method implementation: criticality matrix, which according to the collected
preliminary data graphically reflects the criticality of the system components
(stage 7); Pareto diagram which shows the level of criticality inside the system and
makes it possible to compare several different systems (stage 9); Ishikawa's cause and
effect diagram that allows to identify priority areas for developing appropriate
corrective measures (stage 10).</p>
      <p>
        The main purpose of this work is experimental study of method for importance
level assessing of the CII objects in aviation (CAIS) based on criticality analysis of
systems (subsystems) disaster risks. This method was proposed by authors before [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]
and it is based on FMECA technique with proposed improvements for effective
quantitative and qualitative assessment.
3
      </p>
    </sec>
    <sec id="sec-2">
      <title>Proposed method description</title>
      <p>
        Let`s consider in detail step by step of implementation of the proposed method study.
One CAIS from each of the categories defined in [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ] were selected, these are: one air
navigation system; one aircraft onboard information system; one airlines and airports
system.
      </p>
      <p>
        Stage 1. Identifying system components and setting the level of detail
Step 1.1-1.2 The sets of CAIS classes and systems according to [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ], with
n =1, n =2, n =3 and m1 =5, m2 =7, m3 =4 taking into account (1) - (2) and (1) in
[
        <xref ref-type="bibr" rid="ref13">13</xref>
        ] were determined in the following way:
SCАІS = {S1,S2,S3} = {SІSАО,SBSPS,SІSАА} ={{S1.1,S1.2,S1.3,S1.4,S1.5},{S2.1,S2.2,S2.3,S2.4,S2.5,S2.6,S2.7},{S3.1,S3.2,S3.3,S3.4,S3.5}}
= {{SSAE,SRZZP,SSSP,SSOD,SSMZ},{SSPS,SSZV,SNAVS,SSSPZ,SOSL,SSVI,SABSK},{SCRS,SGDS,SIDS,SBSP,SDCS}}.
where S1 = SІSАО is set of information systems of air navigation services; S2 = SBSPS
is set of onboard aircraft information systems; S3 = SІSАА is set of airline and airport
information systems, S1.1 = SSAE are aviation telecommunication systems; S1.2 = SRZZP
are radio navigation aids; S1.3 = SSSP are surveillance systems; S1.4 = SSOD are data
processing systems; S1.5 = SSMZ are meteorological support systems , S2.1 = SSPS are
air signal system; S2.2 = SSZV are communication systems; S2.3 = SNAVS are
navigation systems; S2.4 = SSSPZ are collision monitoring and prevention systems;
S2.5 = SOSL are computing systems of aviation; S2.6 = SSVI are information display
systems; S2.7 = SABSK are automatic onboard control systems; S3.1 = SCRS is computer
reservation system; S3.2 = SGDS is global reservation system (reservation); S3.3 = SBSP
is mutual calculations system; S3.4 = SDCS are dispatch management systems.
      </p>
      <p>
        Step 1.3. To determine subsystem sets, we arbitrarily select one set of systems from
each class, for example SSOD , SSSPZ , SGDS and according to (3) in [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ] we present
subsystem sets with r1.4 =5, r2.4 =4, r3.2 =18, where S1.4.1 = SASYPR are automated air
traffic control systems (AATCS); S1.4.2 = SSPPP are automated airspace use planning
systems; S1.4.3 = SESAN are centralized surveillance and distribution systems for the
surveillance data of the European Aviation Safety Organization Eurocontrol;
S1.4.4 = SSOPD are flight data processing and transmission systems; S1.4.5 = SSOAD are
aeronautical information processing and transmission systems; S2.4.1 = STRA are
transponders; S2.4.2 = STCAS are onboard collision avoidance systems (TCAS);
warning systems for dangerous land rapprochement;
S2.4.3 = SSRPZ are early
S2.4.4 = SBMR is airborne radar onboard; S3.2.1 = SAMDS is Amadeus; S3.2.2 = STGDS is
Travelport GDS; S3.2.3 = SSAB is Sabre; S3.2.4 = STRES is TameliaRES; S3.2.5 = SAPSS is
Avantik PSS; S3.2.6 = SABCS is Abacus; S3.2.7 = SACA is AccelAero; S3.2.8 = SAXS is
Axess; S3.2.9 = SIBE is Internet Booking Engine; S3.2.10 = SKUI is KIU; S3.2.11 = SMER is
Mercator; S3.2.12 = SNAV is Navitaire; S3.2.13 = SPATH is Patheo; S3.2.14 = SRAD is Radixx;
S3.2.15 = SAKF is Akeflite; S3.2.16 = STTI is Travel Technology Interactive; S3.2.17 = SWSMS
is WorldTicket Sell-More-Seats; S3.2.18 = SSIR is Siren according to [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ].
      </p>
      <p>Step 1.4. To determine the set of components, we arbitrarily select one subsystem
from each set of subsystems, for example SSOAD , STCAS , SAMDS .</p>
      <p>
        For system SSOAD , with b = 7 , while using (4) in [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ], we present the set of
components in the following way:
СSOAD
      </p>
      <p>7
={ Ci }
i=1
={C1,C2 ,..., C7 }</p>
      <p>={СODSS , СОPD , СMKS , СZVI , СKGZ , СPPR , СZBP } ,
where C1 = СODSS is data processing of the surveillance system; C2 = СОPD is flight
data processing; C3 = СMKS is system monitoring and control; C4 = СZVI is recording
and reproduction of information; C5 = СKGZ is commutation of voice communication;
C6 = СPPR is decision support; C7 = СZBP is ensuring the safety of flights.</p>
      <p>
        Similarly for systems STCAS according to [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ], and SAMDS according to [
        <xref ref-type="bibr" rid="ref15 ref16">15-16</xref>
        ], with
b = 5 та b = 4 while using (4) in [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ] respectively, where C8 = САNT are antennas;
C9 = СBLO is calculator unit; C10 = СVRS is respondent mode S; C11 = СIND are indicators
(installed in the cockpit); C12 = СPYL is control panel; C13 = САTIM is Amadeus Timetable;
C14 = СAAV is Amadeus availability; C15 = СASCH are Amadeus schedules; C16 = СADA is
Amadeus direct access.
      </p>
      <p>Step 1.5. Let us set the minimum level of detail Detmin to describe and decompose
the system. The purpose of the analysis Sij / Sijk is to determine the level of criticality
of possible types of components interruptions that cause loss of their functionality, to
find out their causes, consequences, methods of detection and recommendations for
reducing their criticality.</p>
      <p>Therefore, the description and decomposition are limited by level “system class” /
“system” / “subsystem” / “component” (Si / Sij / Sijk / Ci ) and concern only the effects
of possible interruptions of certain components Ci . Meaning that Detmin = Ci , however,
a more detailed study of the more complex components (subsystems) of CAIS may
consider the case of Detmin = Cij , where Cij are parts of components Ci
( Detmin = Sij ∨ Sijk ∨ Ci / Cij ) etc.</p>
      <p>The
selected
systems
are
limited
by
level</p>
      <p>SІSАО / SSOD / SSOАD / CSOАD ;
SBSPS / SSSPZ / STCAS / СTCAS ; SІSАА / SGDS / SAMDS / CAMDS і and concern only the effects
of possible interruptions of certain components Ci .</p>
      <p>
        Stage 2. Defining the functions of each detected system component. For system
SSOАD , containing a set of components CSOАD , with l = 15 , while using (5) in [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ],
we present the set of functions in the following way:
=F2 {F1, ,..., F15}
=
= {FOSG , FPОІ , FVОІ , FОPD , FKPOL , FPPAT , FVYІ , FDVI , F ZDGZ , FAPR , FPZIT , FVPI , FVVKS , FPAP , FZBP },
where F1 = FOSG is signal processing; F2 = FPОІ is primary information processing;
F3 = FVОІ is secondary information processing; F4 = FОPD is flight data processing;
F5 = FKPOL is flight control; F6 = FPPAT is air patrol; F7 = FVYІ is display and
management of information; F8 = FDVI is documentation and reproduction of
information; F9 = FZDGZ is providing air traffic controllers with land and voice
communications; F10 = FAPR is automation of decision making; F11 = FPZIT is
collision prevention; F12 = FVPI is use of planned information; F13 = FVVKS is
identifying and resolving potential conflict situations; F14 = FPAP is aviation events
warning; F15 = FZBP is ensuring the safety of flights [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ].
      </p>
      <p>
        Similarly for systems STCAS according to [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ] and SAMDS according to [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ], sets of
components СTCAS and CAMDS , with l = 14 and l = 4 , while using (5) in [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ], where
F16 = FPPR are receiving and transmitting radio waves; F17 = FZIL is request of other
aircraft responders; F18 = FOMRL is calculating the location of aircraft; F19 = FVTL is
aircraft trajectory tracking; F20 = FPPRD is transmitting warnings and recommendations on
the VSI / TRA display or other indicators; F21 = FPMPP is the transmission of voice
messages to the pilot through the airplane located in the cockpit of the sound notification
system; F22 = FVNZ is responding to requests in Mode-A, Mode-C and Mode-S from
radar systems of the air traffic control service, as well as from other aircraft equipped with
TCAS; F23 = FODSS is data exchange with compatible systems; F24 = FVPZ is establish a
direct connection using a unique address assigned; F25 = FPDBV is transfer of data from
the barometric height sensor and from the control panel to the TCAS computer unit;
F26 = FVVI is display of vertical speed indicator (VSI) information with the display of
aircondition warnings and recommendations for conflict resolution (TRA); F27 = FYRT is
setting TCAS mode and responding mode-S; F28 = FYKV is setting the UPR radar
response codes; F29 = FPRS is system operation check; F30 = FPIZ is providing (general)
flight information on all airlines during the week; F31 = FFIPP is generating flight
information that has at least one available class for sale or a waiting list; F32 = FVGVR is
display all scheduled flights; F33 = FMODI is the ability to access specific airline
information for sale or to complete a waitlist.
      </p>
      <p>
        Stage 3. Determining the list of possible disasters for each system component.
For system SSOАD set of components CSOАD , with p = 9 , while using (6) in [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ], we
present the set of work interruptions (disasters) in the following way:
      </p>
      <p>
        9
DSOАD = { Di } = {D1, D2 ,..., D9} = {DVNIS , DNOPS , DPFOD , DPNI , DVZZ , DNSD , DVRTZ , DVPKS , DVAF},
i=1
where D1 = DVNIS is detecting a nonexistent signal; D2 = DNOPS is incorrect
estimation of signal parameters; D3 = DPFOD is data processing and distribution
breaches; D4 = DPNI is suspension of receipt of information on flights of aircraft;
D5 = DVZZ is loss or destruction of a recording device; D6 = DNSD is unauthorized
access to the recording device; D7 = DVRTZ is loss of radio or telephone
communication with crews, related dispatch points and other traffic participants;
D8 = DVPKS is the occurrence of potential conflict situations of the PCC; D9 = DVAF is
detection of an emergency factor [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ].
      </p>
      <p>
        Similarly for systems STCAS according to [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ] and SAMDS according to [
        <xref ref-type="bibr" rid="ref15 ref16">15-16</xref>
        ], set
of components СTCAS and СAMDS , with p = 9 and p = 17 respectively, while using
(6) in [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ], were D10 = DVNA is directional antenna failure; D11 = DVOBS is failure of
the system computing unit; D12 = DTCF is “TCAS FAIL”, if there is a failure of the
equipment that is the minimum required for the operation of the TCAS system;
D13 = DXPF is “XPNDR FAIL” failure of the respondant mode-S, occurs in the event
of termination of the receipt of reliable data on the altitude from the barometric
altimeter on the respondant mode-S; D14 = DTCO is “TCAS OFF” (TCAS system is
disabled, or problems occur inside the system; D15 = DVSF is “VSI FAIL” (failure of
the vertical speed indicator), when the vertical speed arrow is not displayed on the
VSI display; D16 = DTDF is “TD FAIL” (failure of air condition indicator) appears
when the system TCAS-2000 is unable to display air warnings; D17 = DRAF is “RA
FAIL” (refusal to issue RA messages) appears when TCAS system is unable to
display recommendations for resolving a conflict situation; D18 = DNPY is malfunction
or failure of the control panel; D19 = DZSD is failure to update dates (periods);
D20 = DNIPA is incompleteness of information about airlines; D21 = DNZI is providing
outdated information;
      </p>
      <p>D22 = DNNI is unreliability of the information provided;
D23 = DNIMP is failure to provide landing information (only schedule is displayed,
regardless of availability); D24 = DVMPK is the inability to buy a ticket unless the
airline has an agreement to sell with Amadeus; D25 = DNZD is inability to find airline
information to alert you to potential threats or to obtain necessary information.</p>
      <p>
        Stage 4. Determining the consequences of each possible disasters. For each
possible work interruption (disaster) of the set DSOАD with q = 10 , while using (7) in
[
        <xref ref-type="bibr" rid="ref13">13</xref>
        ], we present the set of interruption consequences in the following way:
10
ESOАD = { Еi } = {E1, E2 ,..., E10} = {ENPR , EPRSY , EVVPS , EVRLP , ENODD , EVRTZ , EPRVZ , EVNM , EZPS , EPRS},
i=1
where
      </p>
      <p>
        E1 = ENPR is wrong decision-making, due to incorrect analysis of the air
situation; E2 = EPRSY is malfunction of control systems, power supply, communication,
piloting, lack of fuel, interruptions in the life support of the crew and passengers, failure
of engines, destruction of individual aircraft structures; E3 = EVVPS is lack of ability to
track aircraft; E4 = EVRLP is loss of opportunity to investigate a flight incident FI;
E5 = ENODD is inability to evaluate the actions of the operator; E6 = EVRTZ is no radio
or telephone connection; E7 = EPRVZ is violation of recommendations on solving the
collision threat; E8 = EVNM is choosing the wrong maneuver; E9 = EZPS are aircraft
collisions; E10 = EPRS is malfunction of control systems, power supply, communication,
piloting, lack of fuel, interruptions in the life support of the crew and passengers, failure
of engines, destruction of individual aircraft structures [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ].
      </p>
      <p>
        Similarly, for each possible work interruption of sets DTCAS according to [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ] and
DAMDS according to [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ], with q = 3 and q = 6 respectively, while using (7) in [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ],
where E11 = ENVVP is TCAS 2000 system may be temporarily unable to determine the
relative bearing of the conflicting aircraft due to the large roll angle, which causes the
directional antenna to shade; E12 = ENVP is inability to display recommendations for
conflict resolution; E13 = ENVPY
      </p>
      <p>is inability to use the control panel accordingly;
E14 = ENRS is system inability to work in real time; E15 = EVIA is lack of information on
airlines; E16 = ENOOI is inability to get online flight booking information; E17 = EMZGP is
a possible malfunction in the flight schedule or the need to reformat it; E18 = EVPZD are
problems with refueling, the possibility of a collision threat; E19 = ENSP is lack of
awareness of employees, which could lead to the wrong decision.</p>
      <p>
        Stage 5. Identifying signs of work interruption detection. For possible work
interruptions DSOАD , while using (8)-(9) in [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ], with r = 0 (the selected set of
interruptions of work did not show any sign Oi ), and for the set DTCAS , according to [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ]
and DAMDS , according to [
        <xref ref-type="bibr" rid="ref15 ref16">15-16</xref>
        ], with r = 1 and r = 3 respectively, while using (8)-(9)
in [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ], we present the set of signs of work interruption detection in the following way (3):
O
      </p>
      <p>
        4
={ Oi }
i=1
={O1, O2 ,..., O4}
={OVSI , OTIM , OAUS , OSCH } ,
(3)
where O1 = OVSI is VSI/TRA display; O2 = OTIM is Timetable (general schedule
screen); O3 = OAUS is Amadeus Access Update/Amadeus Access Sell; O4 = OSCH is
Schedule (schedule screen). Taking into account (9) in [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ],
E(OVSI , Di ) =E(OTIM , Di ) =E(OAUS , Di ) =E(OSCH , Di ) =1.
      </p>
      <p>
        Stage 6. Identifying ways of detecting work interruptions. For each possible work
interruption of the set DSOАD according to [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ], DTCAS according to [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ] and DAMDS
according to [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ], while using (10) in [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ], with s = 7 , s = 1 , s = 1 respectively, we
present the set of ways of detecting work interruptions in the following way:
=,W5 {W1,W2 ,W3 ,W4 ,W6 ,W7 ,W8 ,W9}
=
(4)
where W1 = WSAZS is automatic dependent surveillance systems; W2 = WSOPD is flight
data processing system (FDPS); W3 = WASAZ are automated aviation security systems;
W4 = WBBRP are on-board multi-channel “black box” flight recorders; W5 = WSGZ are
voice communication systems; W6 = WAZS are automated surveillance,
communications, information processing and on-board collision avoidance systems; W7 = WSZBP
are flight safety systems; W8 = WTCAS are TCAS system; W8 = WAAIR is Amadeus AIR.
      </p>
      <p>Stage 7. Construction of a three-dimensional criticality matrix. For the system SSOАD
we form a criticality table according to such parameters as “probability – weight – number
of interruptions of system operation” and construct a three-dimensional criticality matrix
(Fig. 1 a). Similarly, for systems STCAS and SAMDS we form a criticality table and
construct a three-dimensional matrix (Fig. 1 b and Fig. 1 c, respectively).
a)
b)
c)</p>
      <p>Fig. 1. Three-dimensional criticality matrix for SSOАD (a), STCAS (b) and SAMDS (c)
Stage 8. Calculation of the criticality rank of probable disasters</p>
      <p>
        Step 8.1-8.3. For the SSOАD system, work interruptions D1 = DVNIS , let’s define an
indicator B1 j , B2 j , B3 j as (13)-(15) in [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ], where value of z , x , c is going to be found
according to tab. 5,7,9 in [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]. Similarly, for every possible work interruption of SSOАD , STCAS
and SAMDS systems, let’s define an indicator B1 j , B2 j , B3 j as (13)-(15) in [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ], tab.. 5,7,9
in [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ] and add obtained figures to the report (stage 11, Table 1).
      </p>
      <p>Stage 8.4. Calculation of values for the weighting coefficients of work interruption
consequences. Mentioned coefficients are introduced according to [18].</p>
      <p>
        Step 8.4.1. For example, for the weighting coefficients of work interruption
consequences according to [18], having n = 7 considering (16) in [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ], let’s define a
complete set of criteria of weighting coefficients as follows (5):
      </p>
      <p>7
VK = { VKi} = {VK1, VK2,..., VK7} = {VKKZG , VKEKON , VKVNNS, VKPOLN , VKMZT , VKTRV , VKVSKI}, (5)
i=1
where VK1 = VK KZG is number of citizens involved (health and social consequences);
VK 2 = VK EKON is economic effect; VK3 = VK VNNS is impact on the environment;
VK4 = VKPOLN is political implications; VK5 = VKMZT is territorial reach; VK6 = VKTRV
is duration; VK7 = VKVSKI is interdependence of sectors CI (the consequence of the
destruction of one is the destruction of the others) according to [18].</p>
      <p>It also should be noted that, criteria of weighting coefficients of work interruption
consequences are placed from most important – “7” to least important – “1”.</p>
      <p>
        Step 8.4.2. For example, if n = 1, m1 = 5 using (17) in [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ], let’s represent the set
of coefficients VK1 as follows:
      </p>
      <p>5
VK1 = VKKZG = {VK1j} = {VK1.1,VK1.2,VK1.3,VK1.4,VK1.5} = {VK0−5,VK6−20,VKD100,VKD499,VKB500},
j=1
where VK1.1 = VK0−5 is 0-5 deceased; VK1.2 = VK6−20 is 6-20 deceased; VK1.3 = VKD100 is
21-100 deceased; VK1.4 = VKD499 is 101-499 deceased; VK1.5 = VKВ500 is ≥ 500
according to [18].</p>
      <p>Similarly, for sets of coefficients</p>
      <p>
        VK 2 , VK 2 ,..., VK7 , if n = 2, 7 and
m2 = m3 =m4 =m5 =5 accordingly, using (17) in [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ] let’s represent all sets of
coefficients, where VK2.1 = VKD100M is &lt; 100 mil.; VK2.2 = VKD499M is 100-499 mil.;
VK2.3 = VKD2,9M is 500 mil. – 2,9 bil.; VK2.4 = VKD6,9M is 2,9 bil. – 6,9 bil.;
VK2.5 = VKB7M is &gt; 7 bil.; VK3.1 = VKM1G is &lt;1 ha. or 0,0001% of water resources;
VK3.2 = VKD10G is 1-10 ha, or 0,0001-0,001 % of water resources; VK3.3 = VKD100G is
10-100 ha, or 0,001-0,01 % of water resources; VK3.4 = VKD1000G is 100-1000 ha, or
0,01 - 0,1 % of water resources; VK3.5 = VKB1000G is &gt; 1000 ha, or &gt; 0,1 % of water
resources; VK4.1 = VKMIN
is
minimal; VK4.2 = VKSOCN
is social discontent;
VK4.3 = VKMITG
      </p>
      <p>are rallies, protests; VK4.4 = VKMASZ are riots; VK4.5 = VKREV are
revolutions, wars; VK5.1 = VKOBYD is separate building; VK5.2 = VKSEL is village;
VK5.3 = VKRGN is district, city; VK5.4 = VKOBL is region; VK5.5 = VKDER is country;
VK6.1 = VKDGOD is less than an hour; VK6.2 = VKDOBA is day; VK6.3 = VK3DOB are
3 days; VK6.4 = VK5DOB are 5 days; VK6.5 = VK10DIB are 10 days; VK7.1 = VKMVID is
almost no; VK7.2 = VKNVR are causes no destruction; VK7.3 = VKVR1S are causes
destruction of one sector; VK7.4 = VKVR2S are causes destruction of two sectors;
VK7.5 = VKVR3S are causes destruction of three and more sectors [18].</p>
      <p>
        Step 8.4.3. For the SSOАD system, work interruptions D1 = DVNIS , indicator B3 = 7,
and value of weighting coefficient as (19) in [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ], is calculated as follows:
VKVNIS =
17  3258 + 1380 + 255 + 1260 + 1155 + 140 + 55  =
Di according to (12) in [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ]. For example, for the SSOАD system, work interruption
D1 = DVNIS , let’s calculate the criticality rank R = 5 ⋅ 4 ⋅ 5 = 100 and add obtained
1
figures to the report (stage 11). Similarly, for every possible work interruption of
systems SSOАD , STCAS and SAMDS , let’s calculate interruptions criticality rank and add
obtained figures to the report (stage 11, Table 1).
      </p>
      <p>
        Stage 9. Selection of the list of the most significant (critical) disasters. For the
SSOАD system, work interruptions D1 = DVNIS , calculated interruptions criticality rank
R = 5 ⋅ 4 ⋅ 5 = 100 , according to the criticality determination rule (20) in [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ],
1
D1 = DVNIS reffers to the Middle level, requires the development of corrective
measures to reduce criticality rank. Obtained figures are highlighted in the report (stage
11, Table 1) with the help of various colours, if Di , according to (20) in [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ], refers to
the High criticality level, then Ri in Table 1 is highlighted in black, if Di refers to the
Middle level – in grey, if Di refers to the Low level – in light grey. Similarly, for
every possible work interruption of SSOАD , STCAS and SAMDS systems, let’s rank calculated
values of criticality level as (20) in [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ] and add obtained figures to the report (stage 11,
Table 1). Moreover, on this stage a Pareto bar chart (Fig. 2) is used to spot the list of
most significant (critical) Di .
      </p>
      <p>a)
b)
c)</p>
      <p>
        Fig. 2. Calculation results of Ri for SSOАD (a), STCAS (b) and SAMDS (c)
The diagram is created separately for each Sij (to rank the most significant (critical) Di ,
hence Di are placed on the horizontal axis, and calculated values Ri are ont the vertical
axis (like (12) in [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ]), if Ri &gt; R , then Di is highlighted in black on the diagram, if
k
R0 &lt; Ri ≤ Rk – then Di is highlighted in grey, if Ri ≤ R0 – then Di is highlighted in
light grey. Patero bar charts help spot the list of most significant (critical) work
interruptions. They also make it possible to compare separate systems by the calculated
criticality rank and to identify the system which is the most critical among CAIS. For
the SSOАD system, the most critical work interruption is D7 , rank criticality calculations,
carried out by (12) in [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ], revealed the following result: R7 = 3 ⋅ 6 ⋅ 7 = 126 &gt; Rk = 125 .
For the STCAS system the most critical work interruption are values D12 – D16 , rank
criticality calculations, carried out by (12) in [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ], revealed the following result:
R12 =R13 =R14 =R15 = 126 &gt; Rk = 125; R16 = 144 &gt; Rk = 125. For the SAMDS system most
critical work interruptions are D19 , D22 , D25 rank criticality calculations, carried out by
(12) in [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ], revealed the following result: R19 = 126 &gt; Rk = 125 ; R22 = R25 = 144 &gt; Rk = 125 .
Patero bar charts also made it possible to compare the number of critical work
interruptions of studied systems and found out that STCAS system is the most critical.
      </p>
      <p>Stage 10. Forming a list of corrective measures. To make a a list of corrective
measures for SSOАD , STCAS and SAMDS systems let’s create Ishikawa cause and effect
diagrams [17, 19] (Fig. 3), that graphically reflect the characteristics that cause work
interruptions Di and increase the effectiveness of corrective measures development.
a)
b)
c)
Ishikawa cause and effect diagrams for selected systems has devided all identified Di
by the main causes of their occurrence, namely due to errors of: users (а), software
(b), hardware (c), network technologies (d). Therefore, priority areas for developing
corrective measures for SSOАD and SAMDS systems are elimination of software errors
causes and user errors (b and а on Fig. 3 a and Fig. 3 c), for STCAS system –
elimination of hardware and software related causes (b and c on Fig. 3 b).</p>
      <p>
        Whereafter for every possible work interruption of SSOАD , STCAS and SAMDS
systems, if g =3, g =2, g =1 accordingly, using (21) in [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ], let’s represent a set of
methods to detect interruptions (that corrsespond to High and Middle according to
rule (20) in [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ],) as follows:
      </p>
      <p>6
K = { Ki } = {K1, K2 ,..., K6} = {KPONA , KOROB , KOKPD , KZRTO , KPOBR , KVOAA } ,
i=1
(6)
where K1 = KPONA is directional antenna inspection and repair; K2 = KOROB is
inspection and repair of system’s computer unit, K3 = KOKPD are scheduled review and
repair of data transmission channels; K4 = KZRTO is change of maintenance and repair
regulations; K5 = KPOBR is scheduled review of flight recorders; K6 = KVOAA are
Amadeus AIR components update as scheduled.</p>
      <p>
        The list of necessary corrective measures for SSOАD , STCAS and SAMDS systems, is
presented in [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]. The effectiveness of corrective measures assessment is carried out by
recalculation of Ri (stage 8). Next, we use the initial value Rbegin ( Ri before the Ki
implementation) and final Rfinish ( Ri after the implementation of Ki ): if
Rfinish &lt; Rk
then corrective measures aimed to reduce the rank of criticality can be recommended
for use to provide cybersecurity [20]. Also, we can see which corrective measures can
be implemented and for how much they reduce criticality rank.
      </p>
      <p>Stage 11 – Report generation. At this stage, data obtained in the previous stages
is systematized, visualization of qualitative and calculation of quantitative values of
CAIS criticality is carried out. An example of report creation for SSOАD , STCAS and
SAMDS systems is presented in Table 1.</p>
      <p>Novelty of the paper defines by proposed improvements of the FMECA technique
(settheoretical approach, criticality matrix, Pareto diagram, Ishikawa's cause and effect
diagram etc.). The practical values of this study define by verification of the ability of
different CAIS assessment and potential efficiency to assess criticality of infrastructures in
different industries.
С11
С12
С13
С14
С15
С16
F19
F20
F21
F22
F23
F24
…
F29
F30
F31
F32
F33
D13
D14
D15
D16
D17
D18
D19
D20
D21
D22
D23
D24
D25
E14
E15
E16
E17
E18
E19
W8
W8
W8
W8
W8
W8
W9
W9
W9
W9
W9
W9
W9
3
3
3
4
2
2
3
3
5
4
5
4
6
7
6
7
6
7
4
7
5
6
6
6
6
6
7
7
6
6
7
6
6
3
4
6
4
4
4
126
126
126
144
98
48
126
45
120
144
120
96
144
4</p>
    </sec>
    <sec id="sec-3">
      <title>Conclusions</title>
      <p>In this paper experimental study of proposed by authors FMECA-based method for
importance level assessing of the CII objects in aviation based on criticality analysis of
systems (subsystems) disaster risks was carried out. It was selected three CAIS from
different categories (air navigation systems, aircraft on-board information systems as well
(aeronautical information processing and
as airlines and airports systems): SSOАD
transmission system), STCAS (onboard collision avoidance system, TCAS) and SAMDS
(Amadeus system).</p>
      <p>Three-dimensional criticality matrix as well as Pareto bar charts shows that STCAS
system is the most critical among selected CAIS (5 critical disasters and 3 critical
components). Ishikawa cause and effect diagrams shows that priority areas for developing
corrective measures for SSOАD and SAMDS systems are elimination of software errors
causes and user errors, but for STCAS system – elimination of hardware and software
related causes.</p>
      <p>In the future research study it is planned to develop software that, based on the
proposed method, will allow to conduct an experimental research and confirm the possibility
of determining the importance of different categories of CAIS as well as to assess
infrastructure risks in different industries (power energy, communications etc).
17. Kharchenko V., Andrashov A., Sklyar V., Kovalenko A., Siora O. Gap-and-IMECA-based
assessment of I&amp;C systems cyber security, Advances in Intelligent and Soft Computing,
vol. 170, pp.149-164, 2012.
18. Report on Research Project “Infrastructure”, State Scientific and Research Institute of</p>
      <p>Cybersecurity Technologies and Information Protection, №0114U000038d (Restricted).
19. Т. Yeliseeva, “Analysis of the security for electric isolation valve by AVPKO method”,</p>
      <p>Izvestia TulGU, Technical Sciences, issue 5, pp. 182-186, 2013 (in Russian).
20. Gnatyuk S., Sydorenko V., Polozhentsev A., Fesenko A., Akatayev N., Zhilkishbayeva G.,
Method of cybersecurity level determining for the critical information infrastructure of the
state, CEUR Workshop Proceedings, vol. 2616, pp. 332-341, 2020.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <given-names>S.</given-names>
            <surname>Gnatyuk</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Sydorenko</surname>
          </string-name>
          , Yu. Polishchuk and Yu. Sotnichenko, “
          <article-title>Determining the Level of Importance for Critical Information Infrastructure Objects”</article-title>
          ,
          <source>Proceedings of 2019 Intern. Scientific-Practical Conf. on the Problems of Infocommunications. Science and Technology (PIC S&amp;T</source>
          <year>2019</year>
          ), Kyiv, Ukraine,
          <source>October 08-11</source>
          ,
          <year>2019</year>
          , рр.
          <fpage>829</fpage>
          -
          <lpage>834</lpage>
          ,
          <year>2019</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <given-names>Oleksiy</given-names>
            <surname>Yudin</surname>
          </string-name>
          , “
          <article-title>World experience to determine sectors of critical infrastructure”</article-title>
          ,
          <source>Proceedings of 2nd Scientific-Practical Conf. “Prospective directions of information security”</source>
          , Odesa, ONAT, p.
          <fpage>82</fpage>
          ,
          <year>2016</year>
          (in Ukrainian).
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <given-names>Oleksiy</given-names>
            <surname>Yudin</surname>
          </string-name>
          , “
          <article-title>Analysis of approaches for criteria determinig of objects including to critical infrastructure based on EU example”</article-title>
          ,
          <source>Proceedings of 3rd Intern. ScientificPractical Conf. “Actual Issues of Cybersecurity Ensuring and Information Protection”</source>
          , Kyiv. European University, p.
          <fpage>187</fpage>
          ,
          <year>2017</year>
          (in Ukrainian).
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <given-names>S.</given-names>
            <surname>Gnatyuk</surname>
          </string-name>
          , Zh. Hu,
          <string-name>
            <given-names>V.</given-names>
            <surname>Sydorenko</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Aleksander</surname>
          </string-name>
          , Yu.
          <source>Polishchuk and Kh. Yubuzova. “Critical Aviation Information Systems: Identification and Protection”</source>
          , Cases on Modern Computer Systems in Aviation, USA: IGI Global, pp.
          <fpage>423</fpage>
          -
          <lpage>448</lpage>
          ,
          <year>2019</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <surname>Ted</surname>
            <given-names>G</given-names>
          </string-name>
          .
          <article-title>Lewis, Critical Infrastructure Protection in Homeland Security: Defending a Networked Nation</article-title>
          ,
          <source>Wiley; 3 edition</source>
          , 449 p.,
          <year>2019</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <surname>Gnatyuk</surname>
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Aleksander</surname>
            <given-names>M.</given-names>
          </string-name>
          and
          <string-name>
            <surname>Sydorenko</surname>
            <given-names>V.</given-names>
          </string-name>
          “
          <article-title>Unified data model for defining state critical information infrastructure in civil aviation”</article-title>
          ,
          <source>Proceedings of the 9th IEEE International Conference on Dependable Systems, Services and Technologies (DESSERT2018)</source>
          ,
          <fpage>24</fpage>
          -27 May,
          <year>2018</year>
          , Kyiv, рр.
          <fpage>37</fpage>
          -
          <lpage>42</lpage>
          ,
          <year>2018</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7. Doc 8973 ІСАО “
          <article-title>Aviation Security Manual” (Restricted)</article-title>
          ,
          <source>Edition</source>
          <volume>11</volume>
          , 818 p.,
          <year>2019</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <surname>Komari</surname>
            <given-names>I.E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kharchenko</surname>
            <given-names>V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Babeshko</surname>
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Gorbenko</surname>
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Siora</surname>
            <given-names>A</given-names>
          </string-name>
          .
          <article-title>Extended dependability analysis of information and control systems by FME(C)A-technique: Models, procedures</article-title>
          , application (
          <year>2009</year>
          ),
          <source>Proceedings of 2009 4th International Conference on Dependability of Computer Systems, DepCos-RELCOMEX</source>
          <year>2009</year>
          ,
          <article-title>art</article-title>
          . no.
          <issue>5261027</issue>
          , pp.
          <fpage>25</fpage>
          -
          <lpage>32</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9.
          <string-name>
            <surname>Babeshko</surname>
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kharchenko</surname>
            <given-names>V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Gorbenko</surname>
            <given-names>A.</given-names>
          </string-name>
          “
          <article-title>Applying F(I)MEA-technique for SCADAbased industrial control systems dependability assessment and ensuring”</article-title>
          ,
          <source>Proceedings of International Conference on Dependability of Computer Systems</source>
          , DepCoS - RELCOMEX
          <year>2008</year>
          ,
          <article-title>art</article-title>
          . no.
          <issue>4573071</issue>
          , pp.
          <fpage>309</fpage>
          -
          <lpage>315</lpage>
          ,
          <year>2008</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10.
          <string-name>
            <surname>Gorbenko</surname>
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kharchenko</surname>
            <given-names>V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tarasyuk</surname>
            <given-names>O.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Furmanov</surname>
            <given-names>A. “</given-names>
          </string-name>
          <article-title>F(I)MEA-technique of web services analysis and dependability ensuring”, Rigorous Development of Complex FaultTolerant Systems</article-title>
          . LNCS,
          <volume>4157</volume>
          , Springer, Heidelberg, pp.
          <fpage>153</fpage>
          -
          <lpage>167</lpage>
          ,
          <year>2006</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          11.
          <string-name>
            <surname>Gnatyuk</surname>
            <given-names>S.</given-names>
          </string-name>
          ,
          <source>Multilevel Unified Data Model for Critical Aviation Information Systems Cybersecurity, Proceedings of 2019 IEEE 5th International Conference Actual Problems of Unmanned Aerial Vehicles Developments (APUAVD</source>
          <year>2019</year>
          ), p.
          <fpage>242</fpage>
          -
          <lpage>247</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          12.
          <string-name>
            <surname>Gnatyuk</surname>
            <given-names>S.</given-names>
          </string-name>
          , “
          <article-title>Critical Aviation Information Systems Cybersecurity”, Meeting Security Challenges Through Data Analytics and Decision Support, NATO SPS Series, D: Information</article-title>
          and
          <string-name>
            <given-names>Communication</given-names>
            <surname>Security</surname>
          </string-name>
          . − IOS Press Ebooks, Vol.
          <volume>47</volume>
          , №3, рр.
          <fpage>308</fpage>
          -
          <lpage>316</lpage>
          ,
          <year>2016</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          13.
          <string-name>
            <given-names>F.</given-names>
            <surname>Yanovskiy</surname>
          </string-name>
          ,
          <article-title>Radiolocation systems of aircrafts: study guide, Kyiv</article-title>
          , NAU, 688 p.,
          <year>2012</year>
          (in Ukrainian)
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          14.
          <article-title>System for displaying air situation and airplanes collisions preentions TCAS</article-title>
          ,
          <string-name>
            <surname>ACAS</surname>
            <given-names>II</given-names>
          </string-name>
          ,
          <article-title>Manual for pilots</article-title>
          ,
          <volume>90</volume>
          p.
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          15.
          <article-title>Booking the air transportation in AMADEUS system</article-title>
          . URL: http://www.amadeus.com/cis/documents/aco/cis/Amadeus_Basic_
          <article-title>Course_2011(A5).pdf</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          16.
          <string-name>
            <surname>Austrian</surname>
          </string-name>
          <article-title>Serbian Tourism Programmes Lesson 7 Amadeus AIR</article-title>
          . URL: https://www.slideshare.net/AngelinaNjegus/lesson-7
          <string-name>
            <surname>-</surname>
          </string-name>
          amadeus-air
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>