A Review of Airport Security and Resilience Analysis: Integration of Risk Modelling Frameworks
Abstract
1. Introduction
1.1. Background
1.2. Aim, Objectives, and Paper Structure
- 1.
- Synthesise existing security and resilience frameworks and clarify their roles within a lifecycle-oriented perspective (see Section 3)
- 2.
- Characterise the airport structure and sensor networks that shape vulnerability and exposure (see Section 4)
- 3.
- Develop a structured understanding of the airport threat landscape, including the mechanisms, impacts, and limitations of representative threat scenarios (see Section 5)
- 4.
- Examine and compare existing risk assessment methodologies, with particular emphasis on the role of TVRA (see Section 6)
2. Methodology of Literature Review Strategy
3. Conceptual Framework for Airport Security and Resilience
3.1. Airport Security Framework
3.2. Resilience Framework
3.3. Relationship Between Security and Resilience
4. Airport Structure and Sensor Networks
4.1. Airport Structure
- 1.
- External transport facilities, or the ground access system, connect the airport with surrounding areas and include public transport infrastructure, road networks, and parking facilities. Although not always directly owned by the airport, transport hubs are increasingly integrated, and the need for seamless transfers has made these facilities operationally interdependent with airport systems [44]. In particular, mutual recognition of security screening requires a high level of interoperability between airport and external transport security systems, making their integration into the airport management framework both necessary and practical.
- 2.
- Connect area is the interface between the external transportation facilities and the terminal buildings. This component broadly encompasses the access roads outside the airport’s terminals.
- 3.
- The terminal building is the core airport facility, enabling passenger processing and the transition between landside and airside operations. It is typically divided into authorised and non-authorised areas. Non-authorised areas are publicly accessible and connected to external transport interfaces, including facilities such as ticketing, baggage check-in, and arrival pick-up [41,42,43,45]. In contrast, authorised areas require controlled access, with multiple levels of authorisation depending on user roles. Some zones are restricted to specific staff through authentication, while others are accessible to passengers only after security screening and validation of boarding credentials.
- 4.
- The control tower is the airport’s command centre and is responsible for coordinating airport operations, controlling airside activities, and handling emergencies. It may also house the main computer room for electronic systems, including communications, surveillance, and navigation.
- 5.
- Non-airport movement areas are those for passenger and staff movements and should be constructed to avoid overlap with aircraft movement areas. These areas may contain boarding gateways and ferries.
- 6.
- Aircraft movement areas are those where aircraft travel on land and where access by personnel is to be avoided. These areas typically include aprons, runways, and manoeuvring areas, and may also include connecting taxiways that facilitate aircraft ground movement and operational linkage between different airside zones.
- 7.
- Ground facilities are the facilities and equipment that service the aircraft and may include ground handling areas (refuelling and loading areas), associated infrastructure (lights, signs and ground support lines), cargo and mail processing, as well as other facilities (hangars, firefighting, water supply, and drainage system).
4.2. Airport Sensor Systems
5. Airport Threat Landscape: Definitions, Impacts, and Limitations
5.1. Cyber Threats
- 1.
- AI-enabled adversarial attacks on automated security systems exploit machine-learning vulnerabilities in screening, biometric authentication, and threat detection through adversarial examples, data poisoning, and model inversion [75,76,77]. Consequently, compromised AI systems enable undetected breaches, generate excessive false alarms, and erode trust in automated security, potentially forcing reversion to manual processes.Mitigation measures, including adversarial training, input validation, and ensemble methods, improve robustness but introduce computational overhead and remain vulnerable to adaptive attacks. Trade-offs among accuracy, robustness, and operational speed remain unresolved, with no consensus on acceptable false-positive or false-negative rates in mission-critical applications. In addition, the propagation of adversarial effects across interconnected AI systems is poorly understood, and real-world validation remains constrained by safety and security limitations.
- 2.
- Supply chain compromise of critical airport Information Technology (IT)/Operational Technology (OT) systems involves adversaries infiltrating hardware, software, or firmware during manufacturing, distribution, or maintenance [75,78]. These attacks manifest as backdoors in Supervisory Control and Data Acquisition (SCADA) controllers, compromised biometric firmware, or trojanised updates in air traffic management systems that activate under specific conditions. Consequently, compromised systems enable persistent unauthorised access, data exfiltration, and covert sabotage, bypassing perimeter defences and affecting flight safety, data integrity, and operational continuity.Mitigation measures, including vendor assessments, code signing, and hardware verification, provide partial protection but are constrained by complex global supply chains with inconsistent security standards. These measures lack methods to assess cumulative risk across multi-tier supply chains, particularly for legacy systems with opaque provenance. Detection of dormant compromises triggered under specific conditions remains unresolved. Moreover, international coordination mechanisms for supply chain security are also fragmented.
- 3.
- Insider- and Outsider-facilitated cyberattacks collectively constitute a critical class of cyber threats targeting airport operations, involving both external attackers and malicious or compromised insiders who exploit system vulnerabilities or use legitimate access [75,78,79]. These threats manifest through techniques such as phishing, unpatched vulnerabilities, insider credential misuse, unauthorised queries, or deliberate system misconfiguration, enabling attackers to encrypt critical data (e.g., flight schedules, passenger manifests, maintenance records), exfiltrate sensitive information, turn off essential systems, or support coordinated external attacks. Consequently, such compromises can bypass perimeter defences and lead to system outages that force a transition to manual operations, resulting in flight disruptions, processing delays, and potential safety risks when critical operational data becomes unavailable, while also enabling covert data theft or manipulation with delayed detection.Mitigation measures, including backups, network segmentation, endpoint protection, access logging, behavioural analytics, separation of duties, background checks, and incident response planning, aim to enhance resilience but also reveal underlying propagation mechanisms. In particular, ransomware and related attacks spread across interconnected airport systems through lateral movement enabled by shared credentials, insufficient network isolation, and administrative privileges. The increasing digitalisation and interconnection of airport infrastructures—often without a unified or standardised architecture—facilitate rapid propagation across operational, airline, and governmental systems. This interconnectedness further shapes coordination dynamics during cyber incidents, requiring synchronised responses across multiple stakeholders while simultaneously increasing the risk of cascading disruptions.Nevertheless, significant limitations remain. Backup systems may themselves be compromised during sophisticated ransomware attacks, undermining recovery strategies. Behavioural analytics often suffer from high false-positive rates and limited capability to distinguish malicious intent from legitimate activity, particularly for privileged users or in cases of insider collusion. Moreover, there is a lack of validated models for predicting insider threat likelihood that integrate psychological, organisational, and technical factors. Legal and privacy constraints further restrict the extent of monitoring and data collection in many jurisdictions. In addition, decision-making frameworks regarding ransom payment versus operational disruption remain ethically and legally complex, with limited empirical evidence on recovery timelines, the effectiveness of system restoration, and cascading economic impacts.
- 4.
- Fragmented digitalisation and system integration failures stem from the rapid adoption of digital technologies without a unified architecture, leading to incompatible systems, data silos, and integration vulnerabilities [75,76]. These issues manifest as legacy systems that cannot interface with modern platforms, inconsistent security policies, and cascading failures in which corrupted outputs propagate across systems. Consequently, integration failures lead to data inconsistencies, disruptions in passenger processing, baggage routing errors, and security gaps due to poor information flow, and limit real-time coordination in emergency response.Mitigation measures, including enterprise architecture frameworks, API standardisation, and middleware solutions, improve interoperability but are costly and disruptive to implement in legacy infrastructure. These measures lack validated methods to assess cumulative security risks arising from integration complexity, particularly emergent vulnerabilities stemming from unexpected system interactions. In addition, the propagation of integration failures across dependent systems remains poorly understood, including how to balance integration benefits against increased attack surfaces, and empirical data on real-world failure modes in operational airports remain limited.
- 5.
- Blockchain and distributed ledger vulnerabilities in airport security arise from the adoption of blockchain for identity management, baggage tracking, and credential verification, exposing risks such as 51% attacks, smart contract flaws, private key compromise, and consensus manipulation [77]. These issues manifest as unauthorised credential issuance, tampered baggage records, and denial-of-service through network flooding. Consequently, compromised systems undermine trust in distributed credentials, create irreversible fraudulent records, and introduce processing delays during verification failures or forks.Mitigation measures, including permissioned architectures, smart contract verification, and multi-signature schemes, enhance security but increase system complexity and introduce potential centralisation risks. Trade-offs between decentralisation, performance, and security in aviation contexts remain poorly understood, with no consensus on acceptable latency for safety-critical applications. In addition, the cascading impact of blockchain failures across dependent airport systems, as well as recovery from corrupted or forked ledgers, remains underexplored, and real-world deployment data for validation is limited.
5.2. Physical Threats
- 1.
- Drone intrusions involve unauthorised drones entering airport airspace for surveillance, smuggling, or kinetic attacks [75,80]. These threats manifest as small drones evading detection, swarm attacks overwhelming countermeasures, or weaponised drones targeting aircraft and infrastructure. Consequently, intrusions trigger runway closures, flight diversions, and airspace restrictions, with risks of aircraft collisions during take-off or landing and damage to critical assets. Mitigation measures, including radar detection, Radio-Frequency (RF) jamming, net capture, and geofencing, provide partial protection but struggle with small-drone detection and face legal constraints. Detection systems suffer from high false-positive rates (e.g., birds), and reliable, real-time discrimination between malicious and legitimate drones remains unresolved. In addition, optimal response strategies for simultaneous intrusions are poorly understood, and legal frameworks for countermeasures remain inconsistent across jurisdictions, limiting operational effectiveness.
- 2.
- Vehicle-Borne Improvised Explosive Device (VBIED) involves attackers using vehicles loaded with explosives to breach perimeters or target crowded areas [75]. These attacks cause mass casualties, structural damage, and prolonged airport closures, with cascading impacts on regional air transport and potential secondary attacks during evacuation.Mitigation measures, including standoff distances, vehicle barriers, screening checkpoints, and surveillance, provide protection but must balance security with accessibility for legitimate vehicles. Risk assessment models struggle to account for evolving vehicle types and adaptive attacker tactics. In addition, methods for optimising barrier placement to mitigate both ramming and blast effects while maintaining operational flow remain underdeveloped, as do coordination mechanisms for rapid threat assessment of suspicious vehicles.
- 3.
- Perimeter breaches involve intruders bypassing fencing, gates, or checkpoints to enter restricted airside areas [75,79]. These breaches manifest as fence-cutting, tunnel-digging, credential forgery, or exploitation of maintenance access points, often during shift changes or in adverse weather. Consequently, unauthorised access enables aircraft sabotage, explosive placement, cargo theft, or disruption of ground operations, and delayed detection increases the potential for damage.Mitigation measures, including physical barriers, Closed-Circuit Television (CCTV), motion sensors, and patrols, provide protection but are challenged by large perimeters and environmental factors such as weather and wildlife. Optimal sensor placement and patrol scheduling for complex perimeters remain unresolved optimisation problems, particularly under resource constraints. In addition, the impact of environmental conditions on sensor performance and adaptive security strategies under degraded conditions is poorly understood, and empirical data on real-world breach patterns remain limited.
- 4.
- Long-range attacks, such as standoff weapons Improvised Explosive Devices (IEDs) in terminals and public areas, represent complementary external and internal attack vectors targeting airport infrastructure and passenger concentrations [75]. These threats manifest through attackers using weapons from outside airport perimeters—exploiting adjacent properties, elevated positions, or mobile platforms with clear line-of-sight—as well as through the placement or carriage of concealed explosive devices within terminals, baggage claim areas, or pre-security zones via luggage, suicide vests, or hidden infrastructure devices. Consequently, such attacks can cause mass casualties, aircraft damage, structural destruction, and panic-driven secondary injuries, as well as significant operational disruptions, prolonged terminal closures, and reduced passenger confidence.Mitigation measures, including perimeter surveillance, threat detection systems, coordination with law enforcement, behavioural detection, explosive trace detection, canine units, and public-area monitoring, enhance defensive capabilities but also reflect inherent vulnerabilities in airport systems. For example, the open-access design of pre-security areas facilitates IEDs deployment by allowing attackers to blend into normal passenger flows. Moreover, the need to balance security with operational efficiency limits the use of intrusive screening, creating exploitable gaps across both external and internal attack surfaces.Moreover, significant limitations persist. Comprehensive assessment of all potential standoff positions is resource-intensive and quickly outdated as surrounding environments evolve, and validated models for predicting likely attack locations based on terrain and visibility remain limited. Coordination between airport authorities and external law enforcement is often inconsistent, while balancing open access with effective pre-security screening remains unresolved. In addition, empirical understanding of attacker behaviour is limited, and optimal strategies for screening placement that maximise detection while minimising disruption are not yet well established.
5.3. Social Threats
- 1.
- Malicious, compromised or coerced, and negligent or unintentional insider actions collectively represent a spectrum of insider-related threats in airport environments, arising from individuals with legitimate airside access exploiting privileges either deliberately, under external pressure, or inadvertently [75,79]. Consequently, insider threats bypass perimeter security and screening, enabling high-consequence attacks, criminal activities, or exploitation of system weaknesses, often with delayed detection due to the legitimacy of the insider’s presence and the difficulty of distinguishing malicious intent from normal behaviour.Mitigation measures, including background checks, random employee screening, access logging, behavioural monitoring, employee assistance programmes, reporting mechanisms, security awareness training, and usable, error-tolerant system design, improve resilience but remain insufficient. Behavioural monitoring struggles to infer malicious intent and often yields high false-positive rates; detecting coercion before exploitation is inherently difficult, and human error persists despite training. Furthermore, predictive models for insider threat risk lack reliability, raise privacy concerns, and lack consensus on acceptable monitoring levels. There is limited understanding of the psychological, organisational, and cognitive factors driving insider threats, particularly under high workload and stress. Organisational cultures that support reporting vulnerabilities without negative consequences remain uncommon, and effective intervention strategies, legal protections for coerced individuals, and robust metrics for evaluating security culture are underdeveloped, highlighting the complexity of managing intentional, coerced, and unintentional insider threats in airport operations.
- 2.
- Social unrest in airport environments refers to passenger-driven disturbances arising from stress, uncertainty, or adverse conditions, including anxiety caused by prolonged delays, congestion, theft incidents, or concerns about severe weather and safety. These situations manifest through heightened emotional responses, such as frustration, panic, or agitation, which may escalate into verbal conflicts, non-compliance with procedures, opportunistic criminal behaviour, or crowd disorder in terminals and boarding areas. Consequently, such disturbances can disrupt passenger flow, degrade service efficiency, increase staff workload, and introduce safety risks, particularly in high-density environments where localised incidents may propagate rapidly through crowds.Mitigation measures, including real-time information provision, queue management, visible security presence, incident reporting systems, environmental design (e.g., space layout and signage), and staff training in de-escalation, aim to reduce the likelihood and impact of unrest but remain limited in scope. Passenger behaviour is inherently difficult to predict, especially under conditions of uncertainty, fatigue, or perceived loss of control, and current monitoring systems cannot reliably detect early signs of escalation. Furthermore, there is limited understanding of the combined psychological, environmental, and operational factors that trigger unrest, and predictive models of crowd-level behavioural responses remain underdeveloped. Balancing efficient operations with passenger well-being is also challenging, and quantitative metrics to assess emotional states, perceived service quality, and their impact on operational resilience are lacking, highlighting the complexity of managing low-intensity yet high-impact disturbances in airport systems.
5.4. Environmental Threats
- 1.
- Extreme weather events and climate change impacts include severe weather and long-term climate effects that damage infrastructure and disrupt airport operations [81,82,83]. Such events cause flight cancellations, infrastructure degradation, and safety risks, with cascading impacts across regional air networks and prolonged recovery when multiple systems are affected.Mitigation measures, including infrastructure hardening, drainage systems, backup power, and weather monitoring, improve resilience but are challenged by the increasing frequency and severity of events beyond historical design limits. Predictive models for cascading failures during compound events remain underdeveloped, particularly for interacting hazards such as flooding, power loss, and communication failure. In addition, optimal allocation of resilience investments under uncertain climate futures is poorly understood, methods for assessing vulnerability to novel climate scenarios remain limited, and coordination mechanisms for regional airport resilience during widespread disruptions are underdeveloped.
- 2.
- Seismic events and geological hazards include earthquakes and landslides that damage runways, terminals, and underground infrastructure [81,83]. Such events cause immediate operational shutdowns, extensive structural damage, and cascading failures in fuel, power, and communication networks.Mitigation measures, including seismic design standards, structural reinforcement, and emergency planning, improve resilience but are constrained by the high costs and disruptions associated with retrofitting existing infrastructure. Understanding of how seismic effects propagate across interconnected systems, particularly under complex soil conditions, remains limited. In addition, validated models for post-earthquake functionality assessment that capture cascading failures are lacking, and optimal strategies for rapid damage assessment and prioritised restoration remain underdeveloped.
5.5. CBR Threats
- 1.
- Pandemic disease outbreaks and infectious disease transmission arise from airports acting as hubs for pathogen spread via infected passengers moving through terminals, aircraft, and destination regions [75]. These processes operate through multiple transmission pathways, including spread in high-density environments, fomite-based surface contamination, and the movement of asymptomatic or pre-symptomatic individuals who evade conventional screening mechanisms. Consequently, pandemics lead to passenger volume collapse, workforce shortages, and operational disruptions due to health control measures, while enabling rapid global transmission.Mitigation measures, including health screening, ventilation, sanitation protocols, and passenger tracing, improve resilience but vary in effectiveness depending on pathogen characteristics and compliance. Optimal screening strategies that balance detection, throughput, and resource use remain poorly defined, particularly for asymptomatic or long-incubation diseases. In addition, airport-specific transmission models that incorporate passenger flows, contact networks, and environmental factors remain underdeveloped, and legal and privacy barriers constrain international coordination on health standards and data sharing.
- 2.
- Other CBR attacks involve the deployment of chemical, biological, or radiological agents in terminals, ventilation systems, or aircraft [75]. Such incidents cause mass casualties, widespread contamination requiring decontamination, prolonged closures, and significant psychological and economic impacts.Mitigation measures, including air-quality monitoring, hazmat response teams, and decontamination protocols, improve preparedness but face challenges in detecting novel agents and enabling rapid response. Detection systems for emerging threats lack sufficient sensitivity and specificity for real-time use, often generating disruptive false positives. In addition, validated protocols for rapid triage, decontamination, and evacuation in complex airport environments are limited, and coordination among airport authorities, public health, and emergency services during active events remains underdeveloped.
6. Airport Risk Assessment
6.1. Logic-Based Risk Assessment Approaches
6.2. Probabilistic Risk Assessment Approaches
6.3. Operational and Behaviour-Oriented Risk Assessment Approaches
6.4. TVRA
6.4.1. LF
- 1.
- Target Attractiveness (TA): This sub-factor assesses the relative attractiveness of the Critical Asset for a potential perpetrator. Attractiveness is a judgment-based assessment of several factors: the target’s perceived symbolic value, its strategic or tactical value, the target’s population, and knowledge of the asset/target’s existence.
- Asset value: This indicator is intended to measure the value or importance of the assets stored by the target or the target itself. When processing TVRA for a site, we can consider its investment and strategic significance.
- Flow of people: Under the guidance of the conservative principle, a place should be given a score based on whether it is possible to be exposed to mass passenger flow.
- Knowability: This indicator primarily measures the general public’s understanding of the site or asset.
- 2.
- Historical data/trend (HD): This sub-factor allows us to consider any similar attacks conducted against similar targets or assets in the past.
- 3.
- CAPability (CAP): The level of capability that has been demonstrated to conduct attacks involving the use of the specified threat and/or the capability to amass material and equipment needed to carry out the threat. The purpose of this sub-factor is to measure whether a threat scenario can be implemented at a cost acceptable to the attacker in a given national context.
- Legal cost: Is it legitimate to possess core tools within the national context?
- Material cost: If it takes a certain amount of money to implement a malicious act, it can be considered that the material cost in the threat situation is high. This judgment may require empirical, common-sense-based, or subjective evaluation.
- Time cost: In common sense, better-prepared crimes tend to cause greater harm. However, for an orchestrating attack, the longer the interval between action and implementation, the more likely it is to be discovered in advance. However, in evaluating the likelihood factor, it is sufficient to consider only the relationship between preparation time and attack probability. When the same effect can be achieved, people will always choose a more time-saving method.
- Personnel cost: This parameter measures whether multiple, experienced, or trained criminals are needed to carry out attacks.
- Willpower cost: Although a determined attacker can overcome any obstacle, the high cost of illegal acts may still deter some malicious acts.
- 4.
- Target Deterrence (TD): A judgment-based assessment of the likely effectiveness of the inherent site design characteristics in deterring a threat element from undertaking an attack of the kind specified in the threat scenario. In this case, deterrence is broadly defined as deterrence by denial and deterrence through punishment. Deterrence by denial seeks to deter an action by making it infeasible or unlikely to succeed, thereby denying a potential perpetrator the confidence to attain its objectives. Deterrence by punishment is the idea or theory that the threat of punishment will deter people from committing crimes and reduce the probability and/or level of offending. The primary purpose of this factor is to assess whether the facility can prevent or delay malicious behaviour to achieve deterrence.
- Device deterrence: If a location is equipped with comprehensive security measures, the attacker may abandon the attack or switch targets.
- Personnel deterrence: In addition to equipment, staff behaviours can provide deterrence.
- Device Visibility: Although security measures are in place at some locations, their visibility may be insufficient to deter potential attackers. However, to prevent determined attackers from planning cracking plans, some security devices should be intentionally hidden.
- Resilience deterrence: Sometimes, potential attackers may abandon their plans or shift targets when they see that the impact of their attacks will be eliminated within a short period. Therefore, resilience can sometimes serve as a deterrent.
6.4.2. VF
- 1.
- Location (LO): This sub-factor assesses the asset’s vulnerability based on location and terrain, both within and adjacent to the asset. The score is a judgment-based assessment of several factors: line of sight to the target/asset, terrain features that provide cover, and the terrain’s traversability. The main purpose of this sub-factor is to measure whether an attacker can approach the target at an acceptable cost.
- Access restriction time: For a site, if it does not restrict access at any time, the risk it faces is quite high. However, imposing strict access restrictions during periods of high customer traffic may reduce efficiency and increase costs.
- Access authorisation: The severity of authorisation also determines the vulnerability of assets.
- Access restriction devices and design: This indicator primarily measures the general public’s understanding of the site or asset’s access restrictions.
- Terrain factors: Even without issues with the equipment or design, terrain can increase vulnerability.
- 2.
- Baseline Measures (BM): This sub-factor examines the existing security measures on site or those currently planned for implementation. In this context, a layer of security comprises the perimeter fence, personnel, intrusion detection systems, security operations procedures, access control, and biometrics.
6.4.3. IF
- 1.
- Operational Downtime (OD): This sub-factor assesses the impact on the facility’s operation in the event of a successful attack. It takes into account the availability of redundancy for critical assets/equipment, such as power supplies and cooling systems. If there is no redundancy (i.e., a single point of failure), a devastating attack can disrupt the building’s operations.
- 2.
- Facility Downtime (FD): This sub-factor assesses the extent of physical damage sustained by the facility in the event of a successful attack.
- 3.
- Casualties (C): This sub-factor examines the number and severity of casualties and injuries, derived from the total number of people at the Critical Asset and the type of attack.
- 4.
- Reputation (R): This sub-factor looks at the impact on the reputation of the client, the economic well-being of the client, the politics and reputation of the host-nation government, and the social impact affecting the public.
- The degree of reputation damage: It is difficult to have a quantitative value to represent this parameter fully and accurately. Here, the reduction in passenger flow will be roughly measured.
- The breadth of reputation damage: This range refers to the geographical scale at which the event occurred, which has had a reputational impact on the site or location, regardless of other parameters.
- The depth of reputation damage: This parameter measures whether the reputation impact is limited in the site itself or whether the larger organisation behind it will also be implicated.
- The Recovery Time of Reputation: This parameter is still determined by customer traffic.
- 5.
- Financial Impact (FI): This sub-factor assesses the estimated overall monetary value, including construction costs, replacement costs for systems/equipment, and losses due to operational disruption.
6.4.4. Risk Score
6.4.5. Mock TVRA Process and Applications
- 1.
- LF
- TA: This critical asset occupies the sole passageway connecting the landside to the airside, and all passengers must pass through it. Furthermore, an attack on security screening equipment could severely disrupt airport operations. Consequently, it can be concluded that significant passenger flow converges around this critical asset, its existence is widely known, and an attack on this asset holds both strategic and tactical value. The score for this item is High (H).
- HD: According to the data, there is no record of any artificially manufactured explosions occurring in similar locations within the same city over the past three years. The score for this item is Low (L).
- CAP: Under Chinese laws and regulations, materials for manufacturing portable explosive device casings are readily available, but higher-grade explosives and detonators are strictly controlled. The score for this item is Relatively Low (RL).
- As part of the security infrastructure, personnel operating these facilities constitute security staff, enabling rapid response following an incident. The score for this item is Low (L).
- 2.
- VF
- LO: The critical asset is prominently located, with signage clearly indicating its position within the airport premises. Furthermore, the route from the airport entrance to this critical asset is unobstructed. The score for this item is High (H).
- BM: At the example airport, passengers must undergo anti-terrorism screening using test strips at the airport entrance before approaching this critical asset. Furthermore, the facility at the example airport is protected by multiple layers of security equipment (camera surveillance cameras, security patrols, and other anti-terrorism devices). The score for this item is Low (L).
- 3.
- IF
- OD: Generally speaking, improvised explosive devices can only disrupt one of several security screening lines, thus only partially affecting airport operations. The score for this item is Relatively Low (RL).
- FD: Whilst unable to compromise the entire security screening system, portable explosive devices can inflict severe damage upon their direct targets. The score for this item is relatively Moderate (M).
- C: The explosive power of an improvised explosive device is sufficient to cause death. The score for this item is High (H).
- R: A successful attack on this critical asset through multiple layers of defences using a portable explosive device would cause significant damage to the airport’s reputation. The score for this item is Relatively High (RH).
- FI: Improvised explosive devices may cause damage to equipment, casualties, and a sharp decline in passenger numbers. However, such impacts would not persist for long at the example airport. The score for this item is Relatively High (RH).
7. Conclusions
Funding
Data Availability Statement
Conflicts of Interest
References
- National Protective Security Authority. Critical National Infrastructure. 2024. Available online: https://www.npsa.gov.uk/about-npsa/critical-national-infrastructure (accessed on 27 April 2026).
- ICAO. Safety Management Manual (Doc 9859); International Civil Aviation Organization: Montreal, QC, Canada, 2018. [Google Scholar]
- Eisen, N.D. Systems Theoretic Process Analysis as a Practical Tool for Comprehensive Flight Test Hazard Identification. Ph.D. Thesis, Massachusetts Institute of Technology, Cambridge, MA, USA, 2024. [Google Scholar]
- Kornecki, A.J.; Liu, M. Fault tree analysis for safety/security verification in aviation software. Electronics 2013, 2, 41–56. [Google Scholar] [CrossRef] [Scilit]
- Chen, M.; Chen, Y.; Ma, S. Identifying safety performance indicators for risk assessment in civil aviation. In Proceedings of the IOP Conference Series: Materials Science and Engineering; IOP Publishing: Bristol, UK, 2021; Volume 1043, p. 032010. [Google Scholar]
- Nikolaev, A.G.; Lee, A.J.; Jacobson, S.H. Optimal aviation security screening strategies with dynamic passenger risk updates. IEEE Trans. Intell. Transp. Syst. 2011, 13, 203–212. [Google Scholar] [CrossRef] [Scilit]
- Fenton, N.; Neil, M. Risk Assessment and Decision Analysis with Bayesian Networks; CRC Press: Boca Raton, FL, USA, 2018. [Google Scholar]
- Roelen, A.; Wever, R.; Hale, A.; Goossens, L.; Cooke, R.; Lopuhaä, R.; Simons, M.; Valk, P. Causal modeling using Bayesian belief nets for integrated safety at airports. Risk Decis. Policy 2004, 9, 207–222. [Google Scholar] [CrossRef] [Scilit]
- Wu, Y.; He, S.; Shi, J. A dynamic decision-making approach for cabin unlawful interference emergency disposal using dynamic Bayesian network. Sci. Rep. 2024, 14, 19002. [Google Scholar] [CrossRef] [Scilit]
- Tantai, X. The analysis and optimization of passenger security process of terminal based on Monte Carlo model. In Proceedings of the 2017 2nd International Conference on Materials Science, Machinery and Energy Engineering (MSMEE 2017); Atlantis Press: Dordrecht, The Netherlands, 2017; pp. 420–423. [Google Scholar]
- Wang, X.; Song, C.; Zhuang, J. Simulating a multi-stage screening network: A queueing theory and game theory application. In Game Theoretic Analysis of Congestion, Safety and Security: Networks, Air Traffic and Emergency Departments; Springer: Cham, Switzerland, 2015; pp. 55–80. [Google Scholar]
- Wang, Y.; Meng, F.; Wang, X.; Xie, C. Optimizing the passenger flow for airport security check. arXiv 2023, arXiv:2312.05259. [Google Scholar] [CrossRef] [Scilit]
- Laskey, K.B.; Xu, N.; Chen, C.H. Propagation of delays in the national airspace system. arXiv 2012, arXiv:1206.6859. [Google Scholar] [CrossRef] [Scilit]
- Rossi, R.; Gastaldi, M.; Orsini, F. Systematic literature review X narrative review. Acta Paul. Enferm. 2007, 20, v–vi. [Google Scholar]
- Tricco, A.C.; Lillie, E.; Zarin, W.; O’Brien, K.K.; Colquhoun, H.; Levac, D.; Moher, D.; Peters, M.D.; Horsley, T.; Weeks, L.; et al. PRISMA extension for scoping reviews (PRISMA-ScR): Checklist and explanation. Ann. Intern. Med. 2018, 169, 467–473. [Google Scholar] [CrossRef] [Scilit]
- Page, M.J.; McKenzie, J.E.; Bossuyt, P.M.; Boutron, I.; Hoffmann, T.C.; Mulrow, C.D.; Shamseer, L.; Tetzlaff, J.M.; Akl, E.A.; Brennan, S.E.; et al. The PRISMA 2020 statement: An updated guideline for reporting systematic reviews. BMJ 2021, 372, n71. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Bernardo, W.M.; Nobre, M.R.C.; Jatene, F.B. A prática clínica baseada em evidências: Parte II-buscando as evidências em fontes de informação. Rev. Bras. Reumatol. 2004, 44, 403–409. [Google Scholar] [CrossRef] [Scilit]
- Pae, C.U. Why systematic review rather than narrative review? Psychiatry Investig. 2015, 12, 417. [Google Scholar] [CrossRef] [Scilit]
- Long, F.; Majumdar, A. Casualty Behaviour and Mass Decontamination: A Narrative Literature Review. Urban Sci. 2025, 9, 283. [Google Scholar] [CrossRef] [Scilit]
- Corlett, S.; Mavin, S. Reflexivity and researcher positionality. In The SAGE Handbook of Qualitative Business and Management Research Methods; Sage: London, UK, 2018; pp. 377–399. [Google Scholar]
- Cribbin, T.F. Citation chain aggregation: An interaction model to support citation cycling. In Proceedings of the 20th ACM International Conference on Information and Knowledge Management, Glasgow, Scotland, UK, 24–28 October 2011; pp. 2149–2152. [Google Scholar]
- Lecy, J.D.; Beatty, K.E. Representative literature reviews using constrained snowball sampling and citation network analysis. SSRN Electron. J. 2012. [Google Scholar] [CrossRef] [Scilit]
- Baldwin, D.A. The Concept of Security. In National and International Security; Routledge: London, UK, 2018; pp. 41–62. [Google Scholar]
- Craighead, G. High-Rise Security and Fire Life Safety; Butterworth-Heinemann: Boston, MA, USA, 2009. [Google Scholar]
- Post, R.S.; Kingsbury, A.A.; Schachtsiek, D.A. Security Administration: An Introduction to the Protective Services; Butterworth-Heinemann: Boston, MA, USA, 1991. [Google Scholar]
- Paté-Cornell, E. Risk and uncertainty analysis in government safety decisions. Risk Anal. 2002, 22, 633–646. [Google Scholar] [CrossRef] [Scilit]
- Nisula, J.M. A Risk Management Framework for a Complex Adaptive Transport System. Ph.D. Thesis, Université Paul Sabatier–Toulouse III, Toulouse, France, 2018. [Google Scholar]
- Cox, A.; Prager, F.; Rose, A. Transportation security and the role of resilience: A foundation for operational metrics. Transp. Policy 2011, 18, 307–317. [Google Scholar] [CrossRef] [Scilit]
- Grabo, C.M. Anticipating Surprise: Analysis for Strategic Warning; Center for Strategic Intelligence Research, Joint Military Intelligence College: Bethesda, MD, USA, 2002. [Google Scholar]
- Wolfers, A. “National Security” as an Ambiguous Symbol. Political Sci. Q. 1952, 67, 481–502. [Google Scholar] [CrossRef] [Scilit]
- Thekdi, S.; Aven, T. An enhanced data-analytic framework for integrating risk management and performance management. Reliab. Eng. Syst. Saf. 2016, 156, 277–287. [Google Scholar] [CrossRef] [Scilit]
- Meyer, M.D. The Nation’s Transportation System as a Security Challenge. In Wiley Handbook of Science and Technology for Homeland Security; John Wiley & Sons: Hoboken, NJ, USA, 2008; pp. 1–22. [Google Scholar]
- Paté-Cornell, E.; Cox, L.A. Improving risk management: From lame excuses to principled practice. Risk Anal. 2014, 34, 1228–1239. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Stergiou, C.; Psannis, K.E.; Gupta, B.B.; Ishibashi, Y. Security, privacy & efficiency of sustainable cloud computing for big data & IoT. Sustain. Comput. Inform. Syst. 2018, 19, 174–184. [Google Scholar]
- Metzner, N. A comparison of agent-based and discrete event simulation for assessing airport terminal resilience. Transp. Res. Procedia 2019, 43, 209–218. [Google Scholar] [CrossRef] [Scilit]
- Wang, Y.; Zhan, J.; Xu, X.; Li, L.; Chen, P. Measuring the resilience of an airport network. Chin. J. Aeronaut. 2019, 32, 2694–2705. [Google Scholar] [CrossRef] [Scilit]
- Hosseini, S.; Barker, K.; Ramirez-Marquez, J.E. A review of definitions and measures of system resilience. Reliab. Eng. Syst. Saf. 2016, 145, 47–61. [Google Scholar] [CrossRef] [Scilit]
- Nan, C.; Sansavini, G. A quantitative method for assessing resilience of interdependent infrastructures. Reliab. Eng. Syst. Saf. 2017, 157, 35–53. [Google Scholar] [CrossRef] [Scilit]
- Royal Institute of Navigation. Three Stages for Achieving PNT Resilience in Critical National Infrastructure. 2024. Available online: https://rin.org.uk/mpage/Resilient_PNT_Best_Practices (accessed on 27 April 2026).
- Proctor, A.; Andy, R. A Structured Approach to Achieving System Resilience for Position Navigation and Timing (PNT) Systems (PNT System Resilience). ReThink PNT. 2024. Available online: https://rethinkpnt.com/wp-content/uploads/2022/09/Website_copy_PNT-System-Resilience-two-column.pdf (accessed on 27 April 2026).
- Janic, M. Air Transport System Analysis and Modelling; CRC Press: Boca Raton, FL, USA, 2000. [Google Scholar]
- Horonjeff, R.; McKelvey, F.X.; Sproule, W.J.; Young, S.B. Planning and Design of Airports, 5th ed.; McGraw-Hill: New York, NY, USA, 2010. [Google Scholar]
- Wilke, S. Modelling Airport Surface Safety: A Framework for a Holistic Airport Safety Management. Ph.D. Thesis, Imperial College London, London, UK, 2014. [Google Scholar]
- Meng, Y.; Liu, D.; Rong, W.; Wu, M. Security Check Mutual Recognition between High-Speed Railway and Urban Rail Transit Based on Variable Fuzzy Set Theory. Math. Probl. Eng. 2022, 2022, 6571007. [Google Scholar] [CrossRef] [Scilit]
- Crosby, M.; Steinle, M.; Nobel, K.; Smith, T. Airport Security Vulnerability Assessments; Technical Report; National Safe Skies Alliance, Inc.: Louisville, TN, USA, 2020. [Google Scholar]
- de Neufville, R. Airport Systems Planning, Design, and Management. In Air Transport Management; Routledge: New York, NY, USA, 2020; pp. 79–96. [Google Scholar]
- Li, Y.; Gao, X.; Xu, Z.; Zhou, X. Network-Based Queuing Model for Simulating Passenger Throughput at an Airport Security Checkpoint. J. Air Transp. Manag. 2018, 66, 13–24. [Google Scholar] [CrossRef] [Scilit]
- Nayeem, M.H.; Moradi, S.; Hossain, N.U.I.; Shamsuddoha, M.; Islam, M.S. System Dynamics Modeling for Assessing Operational Performance of an Airport Terminal. Case Stud. Transp. Policy 2025, 19, 101345. [Google Scholar] [CrossRef] [Scilit]
- Pan, Y.; Zhang, X.; Xu, Q.; Liu, H. Reducing Waiting Time at an Airport Security Checkpoint Based on the Queuing Model. In Proceedings of the 2019 IEEE Chinese Control and Decision Conference (CCDC), Nanchang, China, 3–5 June 2019; pp. 3860–3865. [Google Scholar]
- ARUP. Gasan Data Centre Threat Vulnerability & Risk Assessment; Technical Report; ARUP: London, UK, 2023. [Google Scholar]
- Dong, M.; Hayhoe, G.F. Denver International Airport Sensor Processing and Database; Technical Report DOT/FAA/AR-00/17; United States Federal Aviation Administration, Office of Aviation Research: Washington DC, USA, 2000. [Google Scholar]
- Kazda, A.; Caves, R.E. (Eds.) Airport Design and Operation; Emerald Group Publishing Limited: Leeds, UK, 2010. [Google Scholar]
- Young, S.; Wells, A.T. Airport Planning & Management, 7th ed.; McGraw Hill LLC: New York, NY, USA, 2019. [Google Scholar]
- Siddiqui, F.M. Designing Airport Terminal New Facilities by Exploiting Parallel Intelligence and Level of Service Framework. In Proceedings of the 2025 IEEE Integrated Communications, Navigation and Surveillance Conference (ICNS), Brussels, Belgium, 8–10 April 2025; pp. 1–6. [Google Scholar]
- Cui, J.; Wang, X.; Li, X.; Liu, Y.; Ba, P.; Xu, C.; Chyży, T. Design and Implementation of Health Monitoring System for an Airport Terminal Building with a Large-Span Truss Steel Structure. Buildings 2025, 15, 3308. [Google Scholar] [CrossRef] [Scilit]
- Davis, A.; Chang, H. Airport Protection Using Wireless Sensor Networks. In Proceedings of the 2012 IEEE Conference on Technologies for Homeland Security (HST), Waltham, MA, USA, 13–15 November 2012; pp. 36–42. [Google Scholar]
- Shan, J.; Miccinesi, L.; Beni, A.; Pagnini, L.; Cioncolini, A.; Pieraccini, M. A Review of Foreign Object Debris Detection on Airport Runways: Sensors and Algorithms. Remote Sens. 2025, 17, 225. [Google Scholar] [CrossRef] [Scilit]
- Hallowell, S.F.; Jankowski, P.Z. Transportation Security Technologies Research and Development. In Proceedings of the MILCOM 2005–2005 IEEE Military Communications Conference, Atlantic City, NJ, USA, 7–20 October 2005; pp. 1753–1756. [Google Scholar]
- Raja, M.F.; Sutarwati, S. Reconciliation Analysis of Passengers Suspected of Carrying Dangerous and Prohibited Goods at Komodo Labuan Bajo Airport Security Checkpoint. QISTINA J. Multidisiplin Indones. 2023, 2, 317–325. [Google Scholar] [CrossRef] [Scilit]
- van Boekhold, J.; Faghri, A.; Li, M. Evaluating security screening checkpoints for domestic flights using a general microscopic simulation model. J. Transp. Secur. 2014, 7, 45–67. [Google Scholar] [CrossRef] [Scilit]
- Lykou, G.; Moustakas, D.; Gritzalis, D. Defending Airports from UAS: A Survey on Cyber-Attacks and Counter-Drone Sensing Technologies. Sensors 2020, 20, 3537. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Airports Council International. Guide to Airport Performance Measures; Technical Report; Airports Council International: Montreal, QC, Canada, 2012. [Google Scholar]
- Zanni, S.; Lalli, F.; Foschi, E.; Bonoli, A.; Mantecchini, L. Indoor Air Quality Real-Time Monitoring in Airport Terminal Areas: An Opportunity for Sustainable Management of Micro-Climatic Parameters. Sensors 2018, 18, 3798. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Air Transport Action Group. Facts and Figures. 2024. Available online: https://atag.org/facts-figures (accessed on 27 April 2026).
- Global Terrorism Database (GTD). Advanced Search by Years: (Between 1971 and 2020) and Targets: (Airports and Aircraft). 2024. Available online: https://www.start.umd.edu/data-tools/GTD (accessed on 27 April 2026).
- Mujica Mota, M.; Scala, P.; Delahaye, D. Improving Airport Performance Through a Model-Based Analysis and Optimization Approach. In Applied Simulation and Optimization 2; Springer International Publishing: Cham, Switzerland, 2017; pp. 109–129. [Google Scholar]
- de Lange, R.; Samoilovich, I.; van Der Rhee, B. Virtual queuing at airport security lanes. Eur. J. Oper. Res. 2013, 225, 153–165. [Google Scholar] [CrossRef] [Scilit]
- Welch, J.D.; Cho, J.Y.; Underhill, N.K.; DeLaura, R.A. Sector workload model for benefits analysis and convective weather capacity prediction. In Proceedings of the Tenth USA/Europe Air Traffic Management Research and Development Seminar (ATM2013), Chicago, IL, USA, 10–13 June 2013. [Google Scholar]
- Agarwal, R.; Gao, G.; DesRoches, C.; Jha, A.K. Research commentary—The digital transformation of healthcare: Current status and the road ahead. Inf. Syst. Res. 2010, 21, 796–809. [Google Scholar] [CrossRef] [Scilit]
- Braun, T.; Fung, B.C.; Iqbal, F.; Shah, B. Security and privacy challenges in smart cities. Sustain. Cities Soc. 2018, 39, 499–507. [Google Scholar] [CrossRef] [Scilit]
- Nau, J.B.; Benoit, F. Smart Airport: How Technology is Shaping the Future of Airports; Wavestone: Paris, France, 2017. [Google Scholar]
- Alabsi, M.I.; Gill, A.Q. A review of passenger digital information privacy concerns in smart airports. IEEE Access 2021, 9, 33769–33781. [Google Scholar] [CrossRef] [Scilit]
- Thums, J.; Künzel, L.; Klumpp, M.; Bardmann, M.M.; Ruiner, C. Future air transportation and digital work at airports–Review and developments. Transp. Res. Interdiscip. Perspect. 2023, 19, 100808. [Google Scholar] [CrossRef] [Scilit]
- Aven, T.; Krohn, B.S. A new perspective on how to understand, assess and manage risk and the unforeseen. Reliab. Eng. Syst. Saf. 2014, 121, 1–10. [Google Scholar] [CrossRef] [Scilit]
- Koroniotis, N.; Moustafa, N.; Schiliro, F.; Gauravaram, P.; Janicke, H. A holistic review of cybersecurity and reliability perspectives in smart airports. IEEE Access 2020, 8, 209802–209834. [Google Scholar] [CrossRef] [Scilit]
- Zaharia, S.E.; Pietreanu, C.V. Challenges in airport digital transformation. Transp. Res. Procedia 2018, 35, 90–99. [Google Scholar] [CrossRef] [Scilit]
- Koepsel, K.M. Commercial Aviation and Cyber Security: A Critical Intersection; SAE International: Warrendale, PA, USA, 2016. [Google Scholar]
- Elmarady, A.A.; Rahouma, K. Studying cybersecurity in civil aviation, including developing and applying aviation cybersecurity risk assessment. IEEE Access 2021, 9, 143997–144016. [Google Scholar] [CrossRef] [Scilit]
- Bloom, R. Airport Security. In International Encyclopedia of Transportation; Elsevier: Amsterdam, The Netherlands, 2021. [Google Scholar]
- Pascarella, D.; Gigante, G.; Vozella, A.; Sodano, M.; Ippolito, M.; Bieber, P.; Dubot, T.; Martinavarro, E. Evaluation of a resilience-driven operational concept to manage drone intrusions in airports. Information 2023, 14, 239. [Google Scholar] [CrossRef] [Scilit]
- Köpke, C.; Srivastava, K.; Miller, N.; Branchini, E. Resilience quantification for critical infrastructure: Exemplified for airport operations. In Proceedings of the European Symposium on Research in Computer Security; Springer: Cham, Switzerland, 2021; pp. 451–460. [Google Scholar]
- Horton, R.; Trump, B.D.; Trump, J.; Knowles, H.S.; Linkov, I.; Jones, P.; Kiker, G. Performance metrics for resilience of airport infrastructure. Transp. Res. Part Transp. Environ. 2025, 142, 104676. [Google Scholar] [CrossRef] [Scilit]
- Janić, M. Analysing and modelling airport resilience: Robustness, vulnerability and recoverability. J. Airpt. Manag. 2021, 15, 361–389. [Google Scholar] [CrossRef] [Scilit]
- Du, S.; Zhong, G.; Wang, F.; Pang, B.; Zhang, H.; Jiao, Q. Safety risk modelling and assessment of civil unmanned aircraft system operations: A comprehensive review. Drones 2024, 8, 354. [Google Scholar] [CrossRef] [Scilit]
- Federal Aviation Administration. Advisory Circular 150/5200-37A: Introduction to Safety Management Systems (SMS) for Airport Operators; Advisory Circular AC 150/5200-37A; U.S. Department of Transportation, Federal Aviation Administration: Washington, DC, USA, 2007. [Google Scholar]
- de Barros, A.G.; Tomber, D.D. Quantitative analysis of passenger and baggage security screening at airports. J. Adv. Transp. 2007, 41, 171–193. [Google Scholar] [CrossRef] [Scilit]
- Coman, C.; Dobrescu, L.; Ruscă, F.; Bădău, F. A Systems Engineering Approach to Modeling Reliability and Vulnerability in Automated Airport Baggage Networks. In Proceedings of the 2025 IEEE 17th International Conference on Electronics, Computers and Artificial Intelligence (ECAI), Targoviste, Romania, 26–27 June 2025; pp. 1–5. [Google Scholar]
- Stef, J.; Alexei, S.; Richard, C. AbSRiM: An Agent-Based Security Risk Management Approach for Airport Operations. Risk Anal. Off. Publ. Soc. Risk Anal. 2019, 39, 1582–1596. [Google Scholar]
- Omidvar, M.; Zarei, E.; Ramavandi, B. The Bow-Tie Method: A Hybrid System Safety and Risk Analysis Approach for Safety–Critical Sociotechnical Systems. In Safety Causation Analysis in Sociotechnical Systems: Advanced Models and Techniques; Springer: Cham, Switzerland, 2024; pp. 123–149. [Google Scholar]
- Feng, C.M.; Chung, C.C. Assessing the Risks of Airport Airside through the Fuzzy Logic-Based Failure Modes, Effect, and Criticality Analysis. Math. Probl. Eng. 2013, 2013, 239523. [Google Scholar] [CrossRef] [Scilit]
- Balboena Bregalda, M. FMEA Application to Ensure Cybersecurity of Technical Products. Ph.D. Thesis, Technische Universität Wien, Wien, Austria, 2023. [Google Scholar]
- Janssen, S.; Sharpanskykh, A.; Curran, R. Agent-based modelling and analysis of security and efficiency in airport terminals. Transp. Res. Part Emerg. Technol. 2019, 100, 142–160. [Google Scholar] [CrossRef] [Scilit]
- Zhao, W.; Alam, S.; Abbass, H.A. Evaluating ground–air network vulnerabilities in an integrated terminal maneuvering area using co-evolutionary computational red teaming. Transp. Res. Part Emerg. Technol. 2013, 29, 32–54. [Google Scholar] [CrossRef] [Scilit]
- Linero, A.R. A review of tree-based Bayesian methods. Commun. Stat. Appl. Methods 2017, 24, 543–559. [Google Scholar] [CrossRef] [Scilit]
- Jha, M.K. Dynamic Bayesian network for predicting the likelihood of a terrorist attack at critical transportation infrastructure facilities. J. Infrastruct. Syst. 2009, 15, 31–39. [Google Scholar] [CrossRef] [Scilit]
- Natalia, Y.A.; De Cauwer, H.; Neyens, T.; Goniewicz, K.; Somville, F.; Molenberghs, G. A Bayesian network analysis of aviation terrorism attack risks. J. Transp. Secur. 2025, 18, 19. [Google Scholar] [CrossRef] [Scilit]
- Jha, M.K. Applying Bayesian networks to assess vulnerability of critical transportation infrastructure. In Applications of Advanced Technology in Transportation; American Society of Civil Engineers: Reston, VA, USA, 2006; pp. 1–6. [Google Scholar]
- Zhou, X.; Liang, W.; Wang, H. Safety Risk Analysis of Small and Medium-sized Airports Based on Improved Bayesian Network Model. In Proceedings of the 2024 IEEE 4th International Conference on Information Technology, Big Data and Artificial Intelligence (ICIBA), Chongqing, China, 6–8 December 2024; Volume 4, pp. 1650–1655. [Google Scholar]
- Ma, Z.; Xiao, Y.; Chen, X. Research on Passenger 3D View Focus of Attention at Airport Terminal Based on Massmotion. In Proceedings of the IOP Conference Series: Materials Science and Engineering; IOP Publishing: Bristol, UK, 2020; Volume 780, p. 062047. [Google Scholar]
- Moukafih, N.; Zhang, H.; Epiphaniou, G.; Maple, C.; Taylor, S.; Carmichael, L. Semi-automated threat vulnerability & risk assessment (tvra) for medical devices. In Proceedings of the 17th International Conference on PErvasive Technologies Related to Assistive Environments, Crete, Greece, 26–28 June 2024; pp. 687–693. [Google Scholar]
- Avci, O.; Ozbulut, O. Threat and vulnerability risk assessment for existing subway stations: A simplified approach. Case Stud. Transp. Policy 2018, 6, 663–673. [Google Scholar] [CrossRef] [Scilit]
- Rossebø, J.E.; Cadzow, S.; Sijben, P. e TVRA, a Threat, Vulnerability and Risk Assessment Tool for e Europe. In International Conference on Trust Management; Springer: Berlin/Heidelberg, Germany, 2006; pp. 467–471. [Google Scholar]
- Alostaz, Y. TVRA and application to a transit center: A case history study. In Structures Congress 2023; American Society of Civil Engineers: Reston, VA, USA, 2023; pp. 30–38. [Google Scholar]
- Madani, A.; Taj, N. IMS SIP Server security model using the TVRA methodology. Signal Data Process. 2015, 1, 17–32. [Google Scholar]
- Meer, J.D.; Rennoch, A. The ETSI TVRA security-measurement methodology by means of TTCN-3 Notation. In Proceedings of the TTCN-3 User Conference (T3UC) 2011, Bled, Slovenija, 7–9 June 2011. [Google Scholar]
- Institute for Economics & Peace. Measuring The Impact of Terrorism: Global Terrorism Index 2025; Technical Report; Institute for Economics & Peace: Sydney, Australia, 2020; Available online: http://visionofhumanity.org/resources (accessed on 27 April 2026).






| Approach | Representative Methods | Main Functions and Strengths | Main Limitations |
|---|---|---|---|
| Logic-based risk assessment approaches | FTA, ETA, FMEA, Bow-tie analysis | These approaches use formal logical representations to decompose hazards, identify causal pathways, and evaluate barrier performance. FTA identifies combinations of basic causal events leading to an undesired top event. ETA maps alternative success–failure sequences after an initiating event. Bow-tie analysis combines upstream causes and downstream consequences, while FMEA identifies component- or process-level failure modes. | These models rely on static logic and binary event representations, which limit their ability to capture temporal evolution, multi-state behaviour, and conditional dependencies. ETA requires reliable estimates of barrier performance, while FMEA is sensitive to subjective scoring and struggles to represent interdependencies and emergent behaviours. |
| Probabilistic risk assessment approaches | BN, DBN, PRA | These methods support causal probabilistic reasoning under uncertainty, temporal state-evolution modelling, integrated frequency–consequence analysis, and vulnerability assessment. BN supports diagnostic and predictive inference through conditional dependencies. DBN extends this by modelling temporal evolution across time slices. PRA integrates scenario identification, frequency estimation, and consequence modelling. | BN may scale poorly with increasing network complexity, making inference computationally intensive and probability elicitation resource-intensive. DBN adds further temporal data requirements and computational costs. PRA may suffer from incomplete scenarios and simplified representations of human and organisational behaviour. |
| Operational and behaviour-oriented risk assessment approaches | Monte Carlo-based PRA, queueing-network models, discrete-event simulation, ABM, pedestrian-dynamics simulation | These approaches model behavioural, temporal, and spatial dynamics in airport environments. Monte Carlo-based PRA and queueing simulations support the evaluation of equipment failures, stochastic demand, waiting times, queue lengths, staffing, and lane configurations. ABM represents passengers, operators, and attackers as autonomous agents, while pedestrian-dynamics simulation models continuous-space movement and crowd-density effects. | These approaches require accurate stochastic inputs, failure distributions, detailed geometric data, movement data, and behavioural assumptions. They also face calibration and validation challenges because empirical data for rare or security-sensitive events are limited, and computational demands increase with scenario complexity. |
| TVRA | Parameterised likelihood–vulnerability–impact assessment | TVRA hierarchically decomposes the security research framework into more quantifiable sub-parameters. It calculates risk through likelihood, vulnerability, and impact factors, and supports the prioritisation of identified risk points. It offers clear objectives, supports targeted research into specific threat scenarios or critical assets, reduces the burden of data collection and analysis, and can be adapted to similar scenarios through modified sub-parameter definitions. | TVRA requires explicit definitions of critical assets and potential threat scenarios, which may increase time and resource expenditure. It does not fully account for mutual impacts across different threat scenarios, and the quantified sub-parameters are based on comparative analysis rather than precise data. Therefore, it should be integrated with other risk analysis approaches or complementary methods to calibrate or refine the results. |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Li, L.; Li, Y.; Ochieng, W.Y.; Proud, W.G.; Huang, M.; El Hajj, M.; Majumdar, A. A Review of Airport Security and Resilience Analysis: Integration of Risk Modelling Frameworks. Appl. Sci. 2026, 16, 5406. https://doi.org/10.3390/app16115406
Li L, Li Y, Ochieng WY, Proud WG, Huang M, El Hajj M, Majumdar A. A Review of Airport Security and Resilience Analysis: Integration of Risk Modelling Frameworks. Applied Sciences. 2026; 16(11):5406. https://doi.org/10.3390/app16115406
Chicago/Turabian StyleLi, Lintong, Yunhao Li, Washington Yotto Ochieng, William Graham Proud, Mingyang Huang, Mireille El Hajj, and Arnab Majumdar. 2026. "A Review of Airport Security and Resilience Analysis: Integration of Risk Modelling Frameworks" Applied Sciences 16, no. 11: 5406. https://doi.org/10.3390/app16115406
APA StyleLi, L., Li, Y., Ochieng, W. Y., Proud, W. G., Huang, M., El Hajj, M., & Majumdar, A. (2026). A Review of Airport Security and Resilience Analysis: Integration of Risk Modelling Frameworks. Applied Sciences, 16(11), 5406. https://doi.org/10.3390/app16115406

