{"id":2420,"date":"2024-01-25T22:00:00","date_gmt":"2024-01-25T22:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/cloud-security\/airline-experiments-with-sase-to-improve-overall-security"},"modified":"2024-01-25T22:00:00","modified_gmt":"2024-01-25T22:00:00","slug":"airline-gets-sase-to-modernize-operations","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/01\/25\/airline-gets-sase-to-modernize-operations\/","title":{"rendered":"Airline Gets SASE to Modernize Operations"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt874546c7e2605f1b\/65b2cca9c8dd95040a248a4f\/hkg-Boaz_Rottem-alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/airline-gets-sase-to-modernize-operations.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/airline-gets-sase-to-modernize-operations.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Complaints like delayed and canceled flights, lost and damaged luggage, and customer service issues are pervasive in the airline industry. What&#8217;s not heard as often \u2014 but may be even more insidious \u2014 are the cybersecurity incidents.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Modern aviation is a mix of legacy and new technology, which creates a complex environment that is difficult to secure. Aviation systems rely heavily on machine learning and artificial intelligence, augmented reality, cloud technology, and the Internet of Things, all of which expand the attack surface. Older, less safe protocols are still in use in critical functions, providing adversaries with even more opportunities to attack. For example, the protocol used to communicate between the pilot and the ground staff is still unencrypted, so communications can be intercepted and tampered with.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Airlines also typically rely on hundreds of service providers to manage various aspects of their operations. A supply chain issue in how the software applications are built or a hardware flaw in the systems can reverberate all the way to the aircraft and people aboard.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">And airline cybersecurity incidents are growing. In 2020 alone, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/socradar.io\/threat-landscape-in-the-aviation-industry-for-h1-of-2023\/\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">more than 40<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> aviation-related cybersecurity events were reported. Top vectors included distributed denial-of-service (DDoS) attacks, data breaches, and ransomware. <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/application-security\/microsoft-links-moveit-attack-cl0p-british-airways-fall\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">British Airways<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/cathay-pacific-suffers-largest-airline-breach\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">Cathay Pacific<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> have experienced large data breaches in recent years, and a 2021 compromise at <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/air-india-confirms-data-of-4-5m-travelers-compromised\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">global aviation industry IT supplier SITA<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> impacted airline bookings. Pilot application data for <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/pilot-applicant-information-for-american-southwest-hacked-\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">American and Southwest Airlines<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> was stolen through a recruitment portal in 2023.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Faced with a growing cybersecurity problem and the need to modernize technology operations, Cathay, a travel lifestyle brand that includes major airline Cathay Pacific, decided to replace its infrastructure with one that has cybersecurity built in.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\">Consider Security When Modernizing<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The pandemic, and the associated shift to hybrid work and boom in cloud usage, highlighted the limitations of Cathay&#8217;s aging infrastructure. Cathay&#8217;s bandwidth requirements surged from about 600 Kbit\/s before the pandemic to about 4 Mbit\/s after. Cathay started by replacing a 40-year-old multiprotocol label switching (MPLS) network the airline relied on for communication with its nearly 200 offices around the world. The network couldn&#8217;t keep up with demand, endpoint visibility was limited, application performance suffered, and it was woefully inadequate when it came to security.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The only security control we had with MPLS was access control over network devices, which meant that even if we wanted to investigate a potential breach or incident, it was a struggle for the security operations team to drill down far enough,&#8221; says Rajeev Nair, general manager of IT infrastructure and security at Cathay Pacific.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">MPLS had to go. Cathay needed a replacement cloud-based technology capable of managing the requirements of a modernized infrastructure and providing end-to-end visibility across VPNs, SD-WANs, and other cloud resources. Eventually, the company selected secure access service edge (SASE), which provides data-centric capabilities like data loss and leakage protection, as well as reduces the need for users to try to circumvent existing security controls.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The SASE model of having security capabilities delivered as a service is a viable way for organizations to optimize their own security efforts,&#8221; says Fernando Montenegro, senior principal analyst for cybersecurity at Omdia. &#8220;The SASE approach with regional points of presence for security services and advanced traffic engineering can improve user experience. And for ongoing management, SASE can both centralize security policy management, which makes it clearer and more consistent, and simplify edge configurations.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">These security features were also important to Cathay since the traditional network perimeter is less effective in a cloud-native environment. SASE-based solutions use a zero-trust security model, which is crucial to controlling devices, identity-based access, and networks, Nair says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;SASE provide networkwide security protection, which is a huge improvement as we move more toward remote working and [improving] employee engagement and experience,&#8221; he adds.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\">Blue Skies Ahead With SASE<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The Cathay team made a conscious decision to avoid products supported by large telecommunications companies because of concerns about agility, future capabilities, and speed to market. After several years-long proof-of-concept experiments, Cathay ultimately chose Aryaka&#8217;s unified SASE.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">With this solution, network operations services ensure that all security events covering different locations and types are properly logged and acted on, including behavior analysis. In addition, the secure Web gateway, which is part of the service, will help ensure that Cathay&#8217;s policies and controls are in place regardless of which network devices connect from or to. Finally, the solution enhances security by enforcing role-based policies and provides safe browsing regardless of browser used, location, or network.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Over time, many of the functions Cathay is looking for other tools to provide may be added to SASE solutions, Omdia&#8217;s Montenegro says. SASE has been integrating technologies such as SD-WAN, secure Web gateways, firewall-as-a-service, and zero-trust access, and vendors continue to innovate by adding new capabilities. Functions like browser security, data security posture management, and cloud security are key areas of interest for SASE vendors.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Nair&#8217;s group is currently finishing up the pilot phase implementation of the solution, which consists of deploying the technology to five to 10 of the company&#8217;s 200 sites. Based on the learnings from that, the team will refine the timeline and approach for the remaining sites.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;We want to make sure we have visibility across the sites in terms of network performance and how security elements are monitored and controlled,&#8221; Nair explains. The pilot also will test ease of deployment, policy management across regions, and performance. The second part of the pilot phase will expand the solution to include airports.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">To ensure full monitoring and control, the new implementation will take advantage of Aryaka&#8217;s unified platform for secure access across applications, workloads, and devices. It will also incorporate Aryaka&#8217;s cloud access security broker (CASB) \u2014 part of its secure services edge, a subset of its SASE solution \u2014 to discover users&#8217; activities on unsanctioned apps and apply appropriate controls. To ensure security at scale, Cathay will use the incorporated firewall as a service, which is applied at the service edge layer.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Once the pilot phase has concluded, full implementation, including integration with more than 400 applications in the public cloud, will begin. It&#8217;s a big change; today, all traffic originates from headquarters in Hong Kong and travels through various hubs to reach its final destination. Once fully implemented, traffic will connect to the nearest Aryaka hub or circuit, and then connect back to the cloud provider.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">When fully operational, Cathay Pacific will be one of the first airlines to embrace SASE \u2014 but it won&#8217;t be the last. In November, Qatar Airways announced that it will add SASE to its technology stack to improve connectivity, operational efficiency, and security. United Airlines and Qantas also have indicated moving in the direction of SASE.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Over time, Nair plans to make other security enhancements. Next up is bringing security closer to end users. To do that, the team plans to upgrade the firewalls and software Web gateways in its data centers and public cloud environment, separate from the SASE solution.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cloud-security\/airline-experiments-with-sase-to-improve-overall-security\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Complaints like delayed and canceled flights, lost and damaged luggage,<\/p>\n","protected":false},"author":12,"featured_media":2421,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-2420","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/airline-gets-sase-to-modernize-operations.jpg?fit=1800%2C1012&ssl=1",1800,1012,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/airline-gets-sase-to-modernize-operations.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/airline-gets-sase-to-modernize-operations.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/airline-gets-sase-to-modernize-operations.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/airline-gets-sase-to-modernize-operations.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/airline-gets-sase-to-modernize-operations.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/airline-gets-sase-to-modernize-operations.jpg?fit=1800%2C1012&ssl=1",1800,1012,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/airline-gets-sase-to-modernize-operations.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/airline-gets-sase-to-modernize-operations.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/airline-gets-sase-to-modernize-operations.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/airline-gets-sase-to-modernize-operations.jpg?fit=1800%2C1012&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2420","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=2420"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2420\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/2421"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=2420"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=2420"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=2420"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}