A Novel Semi-Automatic Approach for Security Risk Treatment for U-Space Solutions

Raffaele Elia,Massimiliano Rak,D. Pascarella

Published 2025 in IEEE International Conference on Systems, Man and Cybernetics

ABSTRACT

The European U-space initiative is expected to drive the widespread adoption of drones, which in turn increases the risk of novel and evolving cyberattacks. Consequently, it is essential to prioritize the assessment and treatment of security risks within the design of U-space solutions. As part of the process, security controls must be selected and implemented to strengthen the system’s cybersecurity posture. However, such selection must take into account their costs, effectiveness, and efficiency. On the other hand, choosing the wrong security controls can leave the analyzed solution highly exposed to threat scenarios. Accordingly, manual security risk treatment could be impractical, especially for highly automated and interconnected systems like U-space. This paper introduces an innovative semi-automatic approach for the security risk treatment of U-space solutions, introducing a bridging between some established frameworks. In detail, the work proposes a systematic integration between the NIST CyberSecurity Framework (CSF) and the Security Risk Assessment Methodology (SecRAM), with the latter representing the main point of reference within the Single European Sky ATM Research (SESAR) programme. The paper demonstrates the effectiveness and cost-efficiency of the approach in developing secure U-space systems through a case study on pharmaceutical delivery in a U-space environment.

PUBLICATION RECORD

CITATION MAP

EXTRACTION MAP

CLAIMS

  • No claims are published for this paper.

CONCEPTS

  • No concepts are published for this paper.

REFERENCES

Showing 1-16 of 16 references · Page 1 of 1

CITED BY

  • No citing papers are available for this paper.

Showing 0-0 of 0 citing papers · Page 1 of 1