sabre airline solutionssabre airline solutions · • passengggy( p)er to travel agency (online or...

28
Sabre Airline Solutions Sabre Airline Solutions Sabre Airline Solutions Sabre Airline Solutions Securing Airline Information Securing Airline Information on the Ground and in the Air 7 November 2012 Kuala Lumpur Malaysia on the Ground and in the Air 7 November 2012 Kuala Lumpur Malaysia Kuala Lumpur, Malaysia Kuala Lumpur, Malaysia Confidential

Upload: others

Post on 20-Jun-2020

10 views

Category:

Documents


1 download

TRANSCRIPT

Page 1: Sabre Airline SolutionsSabre Airline Solutions · • Passengggy( p)er to travel agency (online or in person) • Agency to airline or airline booking system • Booking system to

Sabre Airline SolutionsSabre Airline SolutionsSabre Airline SolutionsSabre Airline SolutionsSecuring Airline Information Securing Airline Information on the Ground and in the Air

7 November 2012

Kuala Lumpur Malaysia

on the Ground and in the Air7 November 2012

Kuala Lumpur MalaysiaKuala Lumpur, MalaysiaKuala Lumpur, Malaysia

Confidential

Page 2: Sabre Airline SolutionsSabre Airline Solutions · • Passengggy( p)er to travel agency (online or in person) • Agency to airline or airline booking system • Booking system to

Brief

Paul FeheleyPaul FeheleyyyPrincipalPrincipalSabre Airline SolutionsSabre Airline SolutionsSouthlake, Texas USASouthlake, Texas USA

Confidential 2

Page 3: Sabre Airline SolutionsSabre Airline Solutions · • Passengggy( p)er to travel agency (online or in person) • Agency to airline or airline booking system • Booking system to

Common Threats Across All Industries

Some threats on airline computer systems not unique to the travel and transport industry

• Hacking, hijacking of data• Threats including service disruption

Th ft f l i f ti• Theft of personal information

Confidential 3

Page 4: Sabre Airline SolutionsSabre Airline Solutions · • Passengggy( p)er to travel agency (online or in person) • Agency to airline or airline booking system • Booking system to

Common Responses

Preventative – avoid the threat before it becomes a threatActive – continuous and realtime detection of threat or fraudPost-mortem – investigate, communicate and refine

Confidential 4

Page 5: Sabre Airline SolutionsSabre Airline Solutions · • Passengggy( p)er to travel agency (online or in person) • Agency to airline or airline booking system • Booking system to

What Does Make Airlines Unique / Cybersecurity?

• The nature of legacy airline systems• Sabre reservations system introduced: 1962y

• 50 years is a long time in IT

Confidential 5

Page 6: Sabre Airline SolutionsSabre Airline Solutions · • Passengggy( p)er to travel agency (online or in person) • Agency to airline or airline booking system • Booking system to

What Does Make Airlines Unique / Cybersecurity?

• The complexity of the global network required to serve airlines (and inter-airline), travel agencies, and passengers themselves

• The threat to human safety inherent in travel and transport and the spectacular nature of mishapsspectacular nature of mishaps

• The unique relationship required between government agencies and travel and transport providers• Airlines carry passengers across country and state borders and therefore

have special responsibilities not tied to other industries

• The amount of personal passenger data required to be collected by travel providers – and the “chain of care” for that data

Confidential 6

travel providers and the chain of care for that data

Page 7: Sabre Airline SolutionsSabre Airline Solutions · • Passengggy( p)er to travel agency (online or in person) • Agency to airline or airline booking system • Booking system to

What Does Make Airlines Unique / Cybersecurity?

• Sheer volume of passengers• …and transactions

• Larger, faster aircraft

2011: 2 3 billion passenger air trips (est )*2011: 2.3 billion passenger air trips (est.)

2020:“forecasts indicate that passenger traffic will grow at the rate of 4.1% per annum equating to 7 4 billion passenger air trips byequating to 7.4 billion passenger air trips by 2020”**

Source: *Collaborative Forum of Air Transport Stakeholders ** Airports Council International

Confidential 7

Page 8: Sabre Airline SolutionsSabre Airline Solutions · • Passengggy( p)er to travel agency (online or in person) • Agency to airline or airline booking system • Booking system to

© planefinder.net

Confidential 8

Page 9: Sabre Airline SolutionsSabre Airline Solutions · • Passengggy( p)er to travel agency (online or in person) • Agency to airline or airline booking system • Booking system to

Passenger Data – a Wealth of Private Information

Confidential 9

Page 10: Sabre Airline SolutionsSabre Airline Solutions · • Passengggy( p)er to travel agency (online or in person) • Agency to airline or airline booking system • Booking system to

Passenger Data – a Wealth of Private Information

Typical international travel records contain• Names of all travelers and “Biodata”: age, nationality

• Including travel partners – with whom are you traveling?

• Personal data: home and overseas addresses, credit card data, emergency contact detailsg y

• Passenger journey details (air, rail, cruise, hotel, car)• ATC - authorization to carry (government permission such as visa)• Seating data (where will you sit when you travel and with whom are

you seated)• Baggage data (how many pieces, weigh of each, owner of each)Baggage data (how many pieces, weigh of each, owner of each)• Special requests of the airlines (meals, wheelchairs, special needs)

Literally hundreds of data items collected, transmitted, reviewed, stored

Confidential 10

Page 11: Sabre Airline SolutionsSabre Airline Solutions · • Passengggy( p)er to travel agency (online or in person) • Agency to airline or airline booking system • Booking system to

Passenger Data – a Wealth of Private Information

Future - travel records may also contain - ?• IP address(es) of your interactions with agencies,

i liairlines• Biometric passenger data points for airport or aircraft door

verification (face, iris, fingerprint)• Images

(face, bags)

Confidential 11

Page 12: Sabre Airline SolutionsSabre Airline Solutions · • Passengggy( p)er to travel agency (online or in person) • Agency to airline or airline booking system • Booking system to

Chain of Care – Passenger Data

Can be quite complex• Passenger to travel agency (online or in person)g g y ( p )• Agency to airline or airline booking system

• Booking system to payment system or gateway

• Airline booking system to airport check-in system• Check-in system to onboard staff and other local service providers• Airline to government• Airline to government

Confidential 12

Page 13: Sabre Airline SolutionsSabre Airline Solutions · • Passengggy( p)er to travel agency (online or in person) • Agency to airline or airline booking system • Booking system to

Baseline Definitions

GDS – Global Distribution Systems (bookings – travel agencies)CRS – Central Reservations Systems (bookings – airlines)y ( g )FFP – Frequent Flyer Systems (passenger data – airlines)DCS – Departure Control Systems (airport check-in – airlines)

IndustryIATA International Air Transport Association• IATA – International Air Transport Association

• Governments – local, national and regional travel governance authorities

• Customs, immigration, police, cybersecurity, quarantine/biosecurity

Confidential 13

Page 14: Sabre Airline SolutionsSabre Airline Solutions · • Passengggy( p)er to travel agency (online or in person) • Agency to airline or airline booking system • Booking system to

Risk Assessment Across The Travel Journey

The Customer Travel Process

Customer

Initiation Reservation Embarkation Conclusion

Airport Check-in Physical Border Arrival

Reservations System CRS/GDS

Frequent flyer System

Touch Points

Web Site, Call Center, In-person

Departure Control System DCS

Airline CRM Database

Border Crossing Database

Departure Control System DCS

Data Sources

Other Domestic and International Authority Data Sources

Journey

Confidential 14

Page 15: Sabre Airline SolutionsSabre Airline Solutions · • Passengggy( p)er to travel agency (online or in person) • Agency to airline or airline booking system • Booking system to

Threat Assessment And The Passenger Travel Process

Ch k i /P b d P t b d/ P t i l

Threat Assessment From Reservation to Post arrival

Check -in/Pre -board Analysis

PNR, Check -in Record Border Crossing Record

Border Control

Post -board/Pre -arrival AnalysisReservation Analysis Post -arrival

Analysis

PNR, Profile, FFP, CRM Data

Reservations System CRS (“Res”)

Border Control

Reservations System CRS ( Res )

Frequent Flyer System

Working Air Crew Database

Departure Control System (DCS)

Border Crossing Database

Departure Control System (DCS)

Other Domestic and International Authority Data Sources

QikQik AnalysisQikThreat Analysis

Reservation Booked Check -in Boarding ArrivalIn Air Post Arrival

+3 days-1 yr.

Qik Analysis Qik Threat Analysis Threat Analysis Threat Analysis

Confidential 15

Qik yQik eat a ys s y y y

Page 16: Sabre Airline SolutionsSabre Airline Solutions · • Passengggy( p)er to travel agency (online or in person) • Agency to airline or airline booking system • Booking system to

Physical Document Threats

Physical documents are still very much a part of airline culture• Airline-issued such as boarding passes and baggage tagsg p gg g g• Government issued – including passports, visas• Right-to-travel for example unaccompanied child, doctor permission

Authenticity of these documents –critical because fraudulent documentscritical because fraudulent documents can pose national security threats, flag immigration fraud, aid in human trafficking and more

Airlines often responsible for validating such documents

Confidential 16

such documents

Page 17: Sabre Airline SolutionsSabre Airline Solutions · • Passengggy( p)er to travel agency (online or in person) • Agency to airline or airline booking system • Booking system to

Physical Document Threats – A Progression

Confidential 17

Page 18: Sabre Airline SolutionsSabre Airline Solutions · • Passengggy( p)er to travel agency (online or in person) • Agency to airline or airline booking system • Booking system to

Physical Document Threats – A Progression

Confidential 18

Page 19: Sabre Airline SolutionsSabre Airline Solutions · • Passengggy( p)er to travel agency (online or in person) • Agency to airline or airline booking system • Booking system to

The Way Forward - Electronic Documents?

• Becoming more popular with passengers• …but carry their own level of threaty

• Mobile boarding passes

• NFC / touch / tap check-in

• RFID permanent bagtag

• Bluetooth-aware systems

Confidential 19

Page 20: Sabre Airline SolutionsSabre Airline Solutions · • Passengggy( p)er to travel agency (online or in person) • Agency to airline or airline booking system • Booking system to

The Way Forward - Electronic Passenger Processing

Airlines and passengers embracingelectronic passenger processing

SITA – Airline IT Trends Survey 2012

www sita aero

Confidential 20

www.sita.aero

Page 21: Sabre Airline SolutionsSabre Airline Solutions · • Passengggy( p)er to travel agency (online or in person) • Agency to airline or airline booking system • Booking system to

Fraud

Confidential 21

Page 22: Sabre Airline SolutionsSabre Airline Solutions · • Passengggy( p)er to travel agency (online or in person) • Agency to airline or airline booking system • Booking system to

Cards: Airlines Accept Billions in Payments

PCI compliance: critical• Challenges via telephone: airline call centersg p• Via websites: booking, electronic ticketing• In person: travel agencies, airport and city ticket offices• Using physical devices: airport kiosks• Onboard aircraft: duty free, purchases services (food/upgrade)

Each point of purchase carries its own threatEach point of purchase carries its own threat• Fraud against the airline• Credit card abuse against the passengerg p g

Confidential 22

Page 23: Sabre Airline SolutionsSabre Airline Solutions · • Passengggy( p)er to travel agency (online or in person) • Agency to airline or airline booking system • Booking system to

In-flight – Unique Cybersecurity Considerations

As on-ground technology advances, so does in-air technology

Avionics, better and smarter

“Fly-by-wire” and “glass cockpit”

Passenger centric onboard systemsPassenger-centric onboard systems• IFE, wired and wireless• In-flight wifi, ground-based and satelliteg , g• In-flight mobile: SMS, voice and data

Confidential 23

Page 24: Sabre Airline SolutionsSabre Airline Solutions · • Passengggy( p)er to travel agency (online or in person) • Agency to airline or airline booking system • Booking system to

In-flight Wi-Fi and Mobile

Confidential 24

Page 25: Sabre Airline SolutionsSabre Airline Solutions · • Passengggy( p)er to travel agency (online or in person) • Agency to airline or airline booking system • Booking system to

In-flight and digital / electronic flight bag

Passenger in-flightg gtechnology must notinterfere with in-flightsystems

Confidential 25

Page 26: Sabre Airline SolutionsSabre Airline Solutions · • Passengggy( p)er to travel agency (online or in person) • Agency to airline or airline booking system • Booking system to

In Conclusion – Thank You !Thank You !

Airlines, travel and transport companies face several unique challenges in regard to data security

Mix of legacy and new technologies must all adhere to IT security policies and practicespolicies and practices

Inter-operability among competing companies and government agencies is critical and complex

Travel volume and passenger demand for faster better processing leadTravel volume and passenger demand for faster, better processing lead us into a digital future

Confidential 26

Page 27: Sabre Airline SolutionsSabre Airline Solutions · • Passengggy( p)er to travel agency (online or in person) • Agency to airline or airline booking system • Booking system to

Brief

[email protected]@sabre.com

Confidential 27

Page 28: Sabre Airline SolutionsSabre Airline Solutions · • Passengggy( p)er to travel agency (online or in person) • Agency to airline or airline booking system • Booking system to

Sabre Holdings

Sabre Airline Solutions, the Sabre Airline Solutions logo, Sabre Holdings, Qik, Qik Analysis, and Sabre, are trademarks and / or service marks of an affiliate of Sabre Holdings Corp. All other trademarks, service marks and trade names are the property of their respective owners.

© 2012 Sabre Inc. All rights reserved.

Confidential 28