GAMMA Overview Key Data • Grant Agreement n° 312382 • Starting date: 1st September 2013 • Duration: 48 months (end date 31st August 2017) • Total Budget: 14.837.981 euro Consortium Composition • 8 Countries • 19 partners: 10 Large Industries 3 SMEs 3 Research org. and Universities 3 End-users Consortium Composition • User Group Relevant end-users (ANSPs and airport operators) are already participating in the GAMMA project; nevertheless, some other specific expertise are needed to respond to issues/ new requirements emerging during the project activities. The GAMMA User Group will make possible a stronger co-operation among the main stakeholders of ATM security which, in turn, will ensure that the outcomes of the project will contribute to improve the overall ATM security with respect to emerging threats and European ATM related crisis management. In particular, the User Group, will contribute to: • setting out the shared operational expectations and a complete set of requirements of all actors within the context of GAMMA • ensure that the technological solutions developed within GAMMA respond to the operational requirements identified by the Users • disseminate the GAMMA results within the user community GAMMA Overview: context, approach and objectives Why GAMMA? New Vulnerabilities • While SESAR will improve performance and dependability of ATM, it will open the way to new vulnerabilities due, for instance, to: • increased reliance on distributed enterprise computing • automated flow of information across a ground and airborne network • Cyber attacks will come from many sources and will have a range of possible targets, including civilian, commercial and military systems to damage critical services 6 Why GAMMA? The need for a holistic approach • ATM as a system of system • Domino effects spreading security threats within ATM and beyond • Security Life cycle: from threat prevention to crisis management 7 GAMMA scope and positioning: an end to end approach Security Stakeholder Security Stakeholder ATM sub-system ATM sub-system ATM Domain ATM sub-system ATM sub-system Security Stakeholder ATM sub-system GAMMA: Objectives Develop ATM threat assessment and risk treatment models ATM Security solution Define an ATM Security Security solution architecture GAMMA Objectives Define an ATM Security Management Framework ATM Security solution validation GAMMA Prototypes Develop validation environment Design and develop security prototype components GAMMA Structure GAMMA: a Helicopter view Implementation Proposals Validation Validation Platforms ATM Security Requirements ATM Threat Assessment SESAR ATM Crisis Management ATM physical infrastructure Security ATM CNS Security ATM Cyber Security ATM Security Solution GAMMA Structure Solution Validation Validation Validation Platforms ATM Crisis Management ATM physical infrastructure Security ATM CNS Security ATM Cyber Security WP9 Validation WP6 Security Prototype WP7 Validation environment WP8 Platform Integration WP5 Validation Needs WP4 Security Solution WP3 Framew ATM Threat Assessment Analysis, Requirements and Solution ATM Security Solution ATM Security Requirements WP10 Exploitation Implementation Implementation Proposals WP2 Threat Assessment Project: WBS Vertical Domains WP2 - ATM Threat Assessment Model WP4 - ATM Security Solution WP5 – Definition of Validation Needs WP9 -Validation WP10 –Exploitation, Dissemination and User Group Management CNS WP8 – Platform Integration and Verification Cyber Security WP7 - Validation environment Crisis Management WP6 - Security Prototypes Ground Infrastructure Waterfall linear approach WP3 - ATM Security Management Framework August-14 September-14 October-14 November-14 December-14 January-15 February-15 March-15 July-15 August-15 September-15 December-15 January-16 February-16 May-16 June-16 July-16 August-16 September-16 November-16 December-16 January-17 February-17 March-17 April-17 May-17 July-17 August-17 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 June-17 July-14 10 October-16 June-14 8 9 April-16 April-14 May-14 7 March-16 March-14 6 November-15 February-14 4 5 October-15 December-13 January-14 3 June-15 November-13 2 May-15 October-13 1 April-15 September-13 Gantt chart WP1 PROJECT MANAGEMENT 1.1 1.2 WP2 2.1 2.2 2.3 WP3 3.1 3.2 3.3 3.4 3.5 3.6 3.7 WP4 4.1 4.2 WP5 5.1 5.2 5.3 WP6 6.1 6.2 6.3 WP7 7.1 7.2 7.3 WP8 Project Coordination Strategic Coordination ATM Threat, Vulnerability and Risk Management model 8.1 8.2 WP9 9.1 9.2 WP10 10.1 10.2 10.3 Integration of Validation Platform Verification of Validation Platform System Requirements Validation Context Establishment Risk assessment Risk Treatment ATM Security Management System Implementation 1.1 1.2 1.3 1.4 MS1 1.6 1.7 1.8 MS3 2.1 2.2 2.3 MS2 MS12 3.1 ATM Security Management Framework definition Roles and responsibilities in a Global ATM security management International cooperation Legal and institutional issues for a global ATM security Civill and military cooperation issues Standardisation Human resources and training ATM Security Architecture definition MS8 3.3 3.2 3.4 3.5 MS5 ATM Security Requirements ATM Security Architecture Definition of Validation Needs 4.1 4.2 4.3 MS4 5.1 Scenarios, methods and means for validation exercises System Requirements of Validation Platform Validation Platform Architecture Security prototypes 5.2 5.3 MS6 Prototypes Requirements Prototypes Design & Development Prototypes Integration and verification Validation Environment Validation Environment Requirements Validation Environment Design & Development Validation Environment Integration and verification Platform integration and verification Validation Excercises Analysis of results Exploitation, dissemination and transfer of project results Dissemination of the projects results Exploitation User Group 1.5 6.1 MS10 6.2 6.3 6.4 6.5-6.13 MS10 MS6 7.1 7.2 7.3 7.4 MS7 MS11 8.1 10.1 8.2 MS9 MS13 9.1 9.2 10.3 10.5 10.2 10.4 10.6 GAMMA Solution: a vision GAMMA Solution: A multi-layer architectural vision ILLUSTRATIVE ATM Security Management Aircraft A/G Datalink Ground Mngt Aeronautical Information Mngt Advanced Airspace Mngt En-route ATC Approch ATC Aerodrome ATC Advanced Airspace Mngt Network Information Mngt Airport Airside Operations AOC ATM Airport Landside Operations External Systems Domain impacted by Cyber Security GAMMA Solution: Lower Security Layer Architectural innovations introduced by GAMMA: • Injection of Security at node/asset level • Alert and event identification • Alert and event notification and distribution Some security enhancements introduced by GAMMA: • • • • • • Information Security System Information exchange gateway Secure Satellite Communication system Integrated modular radio security Secure GNSS communication Secure ATC commubnication GAMMA Solution: Higher Security Layer ATM Security Management •Processing of security information originating from ALL the stakeholders at national or international level CERT SOC •Real-time common situation awareness of the security scenario CIRC Single Stakeholder Cyber Security Mngmt (Local SOC) •Command and Control capabilities for Incident Response, Reaction Coordination and Decision Coordination Support •Attack prediction and Cyber Intelligence capabilities, for identification of potential threats and countermeasures in order to reduce risk exposure, also outside the cyber domain © Copyright Finmeccanica. All rights reserved. 18 GAMMA Solution: Intermediate Security Layer GAMMA solution considers the possibility that Local ATM stakeholders include security Security management capabilities: •Planning •Monitoring •Incident Management •Alert/Event collection and distribution CERT SOC CIRC Single Stakeholder Cyber Security Mngmt (Local SOC) GAMMA Solution: Intermediate Security Layer GAMMA solution considers the possibility that Local ATM stakeholders include security Security management capabilities: •Planning •Monitoring •Incident Management •Alert/Event collection and distribution CERT SOC CIRC Single Stakeholder Cyber Security Mngmt (Local SOC) More information available at: www.gamma-project.eu User Group management contacts: Mr. Giuliano D’Auria - GAMMA project coordinator Selex ES, A Finmeccanica Company (Email) : giuliano.dauria@selex-es.com © Copyright Finmeccanica. All rights reserved.