Skip to main content
Top

2019 | OriginalPaper | Chapter

Airline Application Security in the Digital Economy: Tackling Security Challenges for Distributed Applications in Lufthansa Systems

Authors : Balázs Somoskői, Stefan Spahr, Erkuden Rios, Oscar Ripolles, Jacek Dominiak, Tamás Cserveny, Péter Bálint, Peter Matthews, Eider Iturbe, Victor Muntés-Mulero

Published in: Digitalization Cases

Publisher: Springer International Publishing

Activate our intelligent search to find suitable subject content or patents.

search-config
loading …

Abstract

(a)
Situation faced: In the era of pervasive digitalization, the airline IT software industry is facing a number of challenges from the combination of new distribution channels, social media, Big data, Cloud Computing, etc. One of the major challenges in creating smart and scalable software applications is how to tackle security challenges when components are distributed and operated in hybrid and multiple clouds, whose providers may be independent and heterogeneous. The difficulties reside not only in identifying and expressing the desired level of security in the application, but also in how the security guarantees are influenced by the cloud services used.
 
(b)
Action taken: We exemplify the case with a flight scheduling application prototype developed by Lufthansa Systems and explain how novel approaches are used to address security issues during the development of such a prototype by following the MUSA approach. MUSA stands for Multi-cloud Secure Applications and refers to an EU-funded research project that is developing an integrated solution for the development and operation of secure multi-cloud applications accounting for those security aspects from the beginning. We introduce the MUSA Security DevOps framework and lessons learned from using it.
 
(c)
Results achieved: Lufthansa Systems tested MUSA tools in an exercise to create, deploy and control a new secure application prototype. We describe how these tools were used in the context of the case study presented in this paper. We also analyze the impact that they had in the development, deployment, and operation of the multi-cloud prototype. This analysis is done by means of a user-centered evaluation using questionnaires and informal interviews.
 
(d)
Lessons learned: The most important lesson is the importance of a sound risk analysis from which the security decisions are taken. MUSA framework supports the automation of the risk analysis in a per component basis, helping to systematize the creation of the application risk profile. Another important aspect is how implementing a SecDevOps approach in a multi-cloud scenario proves that it is highly valuable to include security topics together with the regular DevOps methodology. Finally, we must underline the need for cloud standards which enable homogeneous cloud service descriptions that ease the comparison of the services and the offered security controls.
 

Dont have a licence yet? Then find out more about our products and how to get one now:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Literature
go back to reference Alberts CJ, Dorofee A (2002) Managing information security risks: the Octave approach. Addison-Wesley Longman Publishing Co., Boston, MA Alberts CJ, Dorofee A (2002) Managing information security risks: the Octave approach. Addison-Wesley Longman Publishing Co., Boston, MA
go back to reference Baah A (2017) Agile quality assurance. Bookbaby, Cork Baah A (2017) Agile quality assurance. Bookbaby, Cork
go back to reference Debski A, Szczepanik B, Malawski M, Spahr S, Muthig D (2018) A scalable, reactive architecture for cloud applications. IEEE Softw 35(2):62–71CrossRef Debski A, Szczepanik B, Malawski M, Spahr S, Muthig D (2018) A scalable, reactive architecture for cloud applications. IEEE Softw 35(2):62–71CrossRef
go back to reference Mohan V, Othmane L (2016) SecDevOps: is it a marketing buzzword? Department of Computer Science, Technische Universität Darmstadt, Darmstadt Mohan V, Othmane L (2016) SecDevOps: is it a marketing buzzword? Department of Computer Science, Technische Universität Darmstadt, Darmstadt
go back to reference Rios E, Iturbe E, Palacios MC (2017) Self-healing multi-cloud application modelling. In: Proceedings of the 12th international conference on availability, reliability and security, p 93. ACM Rios E, Iturbe E, Palacios MC (2017) Self-healing multi-cloud application modelling. In: Proceedings of the 12th international conference on availability, reliability and security, p 93. ACM
Metadata
Title
Airline Application Security in the Digital Economy: Tackling Security Challenges for Distributed Applications in Lufthansa Systems
Authors
Balázs Somoskői
Stefan Spahr
Erkuden Rios
Oscar Ripolles
Jacek Dominiak
Tamás Cserveny
Péter Bálint
Peter Matthews
Eider Iturbe
Victor Muntés-Mulero
Copyright Year
2019
Publisher
Springer International Publishing
DOI
https://doi.org/10.1007/978-3-319-95273-4_3

Premium Partner