Next Article in Journal
Characterization of Dough Rheological Properties and Bread Quality from Different Triticale Varieties and Fermented Dark Brewers’ Spent Grain
Next Article in Special Issue
Energy Savings in Public Lighting by Using Adaptive Street Lighting—A Framework for Energy-Savings Assessment and Machine Learning-Based Evaluation
Previous Article in Journal
Mercury (Hg) Speciation in the Soil–Plant System of Formerly Polluted Soils
Previous Article in Special Issue
An Energy-Efficient Hybrid System Combining Sentinel-2 Satellite Data and Ground-Based Single-Pixel Detector for Crop Monitoring
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
Review

A Review of Airport Security and Resilience Analysis: Integration of Risk Modelling Frameworks

1
Department of Civil and Environmental Engineering, Faculty of Engineering, Imperial College London, London SW7 2AZ, UK
2
Department of Physics, Faculty of Natural Sciences, Imperial College London, London SW7 2AZ, UK
3
Key Laboratory of Intelligent Bionic Unmanned Systems, School of Artificial Intelligence, University of Science and Technology Beijing, Beijing 100083, China
*
Author to whom correspondence should be addressed.
These authors contributed equally to this work.
Appl. Sci. 2026, 16(11), 5406; https://doi.org/10.3390/app16115406
Submission received: 9 April 2026 / Revised: 22 May 2026 / Accepted: 25 May 2026 / Published: 28 May 2026
(This article belongs to the Special Issue Security Aspects and Energy Efficiency in Sensor Networks)

Abstract

Airports, as Critical National Infrastructure (CNI), operate as tightly coupled socio-technical systems exposed to multifaceted threats, including cyber, physical, social, environmental, and Chemical, Biological and Radiological (CBR) threats. This study presents a structured review of the synthesis of conceptual frameworks, airport structural configurations, sensor networks, and multi-domain threat landscapes, as well as airport security and resilience analysis, while comparatively examining risk assessment approaches. The review shows that existing approaches are effective for threat identification and prioritisation but remain predominantly static, with limitations in scalability, data dependency, and real-time applicability. To address these limitations, Threat-Vulnerability-Risk Assessment (TVRA) is adopted as a structured, reusable approach to support metric allocation, redundancy design, and emergency capability development. It further serves as a bridge between traditional risk assessment and resilience-oriented system design by enabling the transformation of static risk scores into scenario-based inputs, thereby supporting stress-testing and lifecycle-based resilience planning across the prepare, act, and recover phases. However, its inherently static structure limits its ability to capture temporal dynamics and cascading interdependencies, highlighting the need to integrate it with dynamic modelling approaches.

1. Introduction

1.1. Background

Airports are mission-critical infrastructures that serve as key nodes in global transportation and logistics networks. They facilitate the movement of people and goods, support economic development, and play vital roles in emergency response and recovery operations. Due to their strategic importance for safety, security, and national stability, airports are classified as part of the CNI in the United Kingdom [1]. With the increasing interconnectivity and digitalisation of airport systems, exposure to diverse threats driven by high passenger density, operational complexity, and increasing digitalisation, including biological, cyber, environmental, physical, and social hazards, has significantly increased (see Figure 1). Consequently, a structured understanding of airport threats, including their mechanisms, impacts, and limitations, provides a critical foundation for proactive risk assessment and resilience-oriented system design.
To systematically analyse such complex and interdependent hazards and risks, airport security and resilience are increasingly conceptualised through structured analytical frameworks. Security frameworks primarily focus on identifying critical assets, characterising threats and risks, and implementing mitigation measures to prevent or reduce the likelihood of adverse events. Resilience frameworks extend beyond prevention, emphasising the system’s capacity to prepare for, respond to, and recover from disruptions while maintaining acceptable levels of functionality. In particular, the preparation phase plays a foundational role by establishing the knowledge base needed to anticipate potential disruptions and design appropriate mitigation and response strategies. Contemporary research, therefore, highlights the need for integrated frameworks that combine risk assessment with lifecycle-based resilience concepts, enabling a transition from static, prevention-oriented approaches to dynamic, performance-oriented system management.
Within such frameworks, related components are essential to support consistent analysis and modelling. Vulnerability represents the susceptibility of critical assets or systems to such hazards, while influence factors capture contextual conditions that may amplify or mitigate both likelihood and impact. Threats denote potential sources of harm or adverse effects, in airport contexts ranging from mechanical failures and human errors to external disruptions such as extreme weather or cyberattacks [2]. Finally, risks reflect both the probability that a hazard will materialise and the severity of its consequences.
Traditional airport safety and security research has predominantly relied on logic-based, probabilistic, and operational and behaviour-oriented analytical frameworks. Logic-based approaches couple causal reasoning with decision-support outputs through structured threat identification, probability assessment, and consequence evaluation [3,4,5,6], but face inherent limitations in complex airport environments characterised by interdependencies, adaptive behaviour, and operational variability. Probabilistic methods enable causal inference under uncertainty, supporting uncertainty propagation, and explicitly modelling temporal dynamics. However, their practical application is constrained by the substantial effort required to elicit probabilities, the scarcity of reliable data on rare security events, and the computational burden of large-scale or real-time inference [7,8,9]. Operational and behaviour-oriented approaches further enhance risk assessment by explicitly modelling behavioural, temporal, and spatial dynamics in airport scenarios, thereby enabling the representation of congestion evolution, adaptive human decision-making, and layout-dependent effects under stochastic demand. These models introduce significant limitations in data requirements, calibration, and computational cost, particularly when modelling rare security events and validating emergent behaviours against limited empirical evidence [10,11,12,13]. These limitations hinder efforts to improve contemporary airport security and resilience.
In response to these limitations, TVRA has emerged as a widely adopted methodology in airport security practice, offering a structured yet flexible approach to risk characterisation under conditions of uncertainty and limited data. Unlike purely quantitative models, TVRA decomposes risk into three core components, threat likelihood, asset vulnerability, and impact, enabling comparative evaluation of heterogeneous threat scenarios through semi-quantitative scoring and expert-informed weighting. This approach is particularly suited to the preparation phase of resilience, as it facilitates the systematic identification of critical assets, the construction of a credible parameter system, and the prioritisation of mitigation strategies before a disruption occurs.
Recent developments in TVRA have further enhanced its applicability by integrating it with complementary analytical approaches, including probabilistic modelling, simulation frameworks, and digital twin environments, thereby improving its capability to capture interdependencies and support scenario-based decision-making. However, TVRA remains inherently static and comparative, with limited ability to represent time-dependent system behaviour, cascading effects, and adaptive responses. Consequently, there is a growing need to integrate TVRA with dynamic, system-level modelling frameworks to bridge the gap between structured risk prioritisation and resilience-oriented performance analysis in complex airport environments.

1.2. Aim, Objectives, and Paper Structure

Building on the above discussion, this paper aims to provide a structured and integrated perspective on airport security and resilience analysis by bridging conceptual frameworks, threat characterisation, and risk assessment methodologies. Specifically, the objectives and paper structures are:
1.
Synthesise existing security and resilience frameworks and clarify their roles within a lifecycle-oriented perspective (see Section 3)
2.
Characterise the airport structure and sensor networks that shape vulnerability and exposure (see Section 4)
3.
Develop a structured understanding of the airport threat landscape, including the mechanisms, impacts, and limitations of representative threat scenarios (see Section 5)
4.
Examine and compare existing risk assessment methodologies, with particular emphasis on the role of TVRA (see Section 6)
The key contribution of this review is to provide an integrated analytical foundation for airport security and resilience analysis, with direct implications for airport planning, risk governance, and policy formulation. Rather than treating security and resilience as separate domains, the paper clarifies their relationship within a lifecycle-oriented perspective, showing how preventive protection, operational act, and post-disruption recovery can be connected. Building on this conceptual basis, the review develops a structured understanding of airport systems by linking functional zones, critical assets, sensor networks, and multi-domain threat scenarios, including cyber, physical, social, environmental, and CBR threats. This provides a systematic basis for identifying where airport vulnerabilities arise, how threats may affect different assets, and which threat–asset combinations require priority attention.
The paper also contributes methodologically by comparing logic-based, probabilistic, and operational or behaviour-oriented risk assessment approaches, and by positioning TVRA as a practical bridge between traditional risk assessment and resilience-oriented system design. Although TVRA is inherently static, its structured outputs can support prioritising mitigation measures, allocating redundancy, developing emergency capabilities, and conducting scenario-based stress testing. In this sense, the review does not merely summarise existing methods, but translates them into an operationally usable pathway for airport decision-making. Its policy relevance lies in offering regulators, airport operators, infrastructure planners, and emergency management agencies a coherent structure for moving from fragmented, compliance-oriented security measures towards risk-informed and resilience-based governance. By connecting asset mapping, threat characterisation, risk prioritisation, and resilience planning, the paper lays the groundwork for a scalable analytical framework to support investment decisions, cross-agency coordination, planning standards, and the future integration of dynamic modelling tools, such as simulation and digital twins.

2. Methodology of Literature Review Strategy

This review examines airport security and resilience challenges by analysing academic publications, engineering and government reports, Non-Governmental Organisation (NGO) reports, and selected grey literature. Its primary aim is to explore how risk analysis methods can support the modelling of airport security and resilience, with emphasis on required data and performance metrics. Accordingly, the review focuses on four aspects: (i) security and resilience concepts, (ii) airport structure, sensors and performance, (iii) a dedicated airport threats landscape, and (iv) potential risk assessment approaches.
Literature reviews are commonly classified as either systematic or narrative, based on their methodological orientation and review objectives [14]. Systematic reviews, guided by frameworks such as Preferred Reporting Items for Systematic Reviews and Meta-Analyses (PRISMA) for scoping reviews [15] and the PRISMA 2020 statement [16], are well suited to addressing narrowly defined research questions through transparent and replicable search strategies. However, these approaches are not fully applicable to this study. This review aims to synthesise guiding principles for constructing airport security models across multiple thematic domains, rather than to answer a single predefined question. Consequently, it prioritises thematic relevance and methodological applicability over exhaustive keyword coverage or rigid inclusion criteria.
Given the aim, the review adopts a narrative review methodology. Narrative reviews allow flexible scope definition and qualitative synthesis across interdisciplinary domains [17], which is essential for addressing the cross-cutting nature of airport security, resilience, critical asset identification, threat characterisation, and risk assessment. Although narrative reviews have been criticised for potential reviewer bias [18], this characteristic is considered acceptable and manageable in this context. The interdisciplinary nature of the topic necessitates informed subjective judgement to identify relevant literature across engineering, safety science, and security studies [19]. To address this limitation, reflexivity is explicitly acknowledged, and methodological decisions are critically examined throughout the review process [20]. In limited cases, expert judgement, informed by the authors’ professional experience, is necessary, particularly when addressing sensitive security-related topics for which publicly available sources are incomplete.
While narrative synthesis forms the core methodological approach, efforts are made to standardise the literature screening process where practicable. Two primary methods for identifying the literature are employed: keyword searching and snowball sampling. Keyword searches are conducted for each thematically defined section using targeted terms such as security research frameworks, airport terminal security incidents, risk assessment methodologies, airport digital twins, human factors in airport safety, and airport infrastructure resilience. Searches are primarily performed using major open-access platforms, including Google Scholar. Owing to the subject matter’s strong industrial relevance and sensitivity, the selected grey literature—including incident investigation reports and news sources—is incorporated as an important supplementary evidence base. In addition, a small number of internal engineering documents from Arup Group’s East Asia division are referenced based on the authors’ professional involvement; access to these materials is subject to organisational authorisation.
To extend coverage, snowballing, also called citation chaining, is used to trace references from core publications [21,22]. This approach supports interdisciplinary synthesis by constructing a connected evidence base capturing both foundational studies and recent developments. The overall process is illustrated in Figure 2.

3. Conceptual Framework for Airport Security and Resilience

3.1. Airport Security Framework

There is no universal concept of security across applications, ranging from no fear, threat and harm in a stable and predictable environment, to the protection of infrastructural and personnel information and assets, to the prevention of unauthorised or detrimental losses [23,24,25]. In this study, airport security means the airport’s critical functions remain uncompromised.
The proposed airport security framework provides a structured methodology for defining and evaluating the security requirements of airport infrastructure, with risk management to be considered primarily in the early design stage, including the system’s ability to withstand disruptions and respond effectively to risks (see Figure 3). Commonly, the protection of humans is prioritised above all other considerations in security requirements, followed by the safeguarding of physical and operational assets [26]. The consideration of framework design mainly includes potential threats, financial constraints, passenger flow efficiency, and malicious actors whose adaptive behaviours, evolving tactics, and ability to conceal intent make threats more difficult to detect, prevent, and manage effectively [27,28,29].
In a seminal exercise, Wolfers proposes a method for defining security within clearly delineated parameters [30]. This approach decomposes security into seven sub-dimensions: the object of security, the core value of security, the degree of security, the threats to security, the means of security, the costs of security, and the temporal scope of security. Within the aforementioned definition, the object of security denotes which systems (structures, personnel, or assets) require examination; the core value of security specifies which functions demand protection; the degree of security refers to the level of ‘critical impact’; and the threat to security identifies which types of incidents warrant investigation. The final three elements, respectively, represent the methods employed to optimise the security system, the resources required for its construction, and the duration for which the designed security system can remain effective. Specifically within the study of infrastructure represented by airports, Thekdi and Aven [31] proposes integrating risk management with other key processes, not only to manage and prevent risks that exceed a specified tolerance, but also to account for performance and risk within a comprehensive risk framework. Within such an integrated framework, the identification and structuring of critical assets, often formalised through an asset map, constitutes the foundational step of the risk analysis process.
Therefore, the initial step in risk analysis is to establish requirements to ensure security and to develop the asset map, which identifies the airport’s critical assets and potential threats requiring attention [26,32,33]. Subsequently, vulnerabilities associated with these asset characteristics should be defined and tested. Testing these characteristics often involves penetration testing to systematically probe defined targets for technical vulnerabilities using a combination of automated tools and manual techniques. For a more comprehensive evaluation of resilience, vulnerability analysis may utilise methods such as path analysis or event trees to estimate the conditional likelihood of damage resulting from the compromise of a specific asset. Under certain conditions, these vulnerabilities can be exploited and turned into threats. Threats are defined as risks that exceed a certain threshold [28,29]. Finally, mitigation measures are proposed and implemented according to the characteristics of each risk [31]. This process is illustrated in Figure 3.

3.2. Resilience Framework

In airport environments, where physical infrastructure, digital systems, passengers and staff, and operational processes are tightly coupled, the resilience should not be treated as a standalone attribute but rather as embedded within system design, governance mechanisms, and performance evaluation frameworks [34]. Similarly to security, there is no universally accepted definition of resilience. Metzner [35] reviews multiple definitions across different application domains, demonstrating that resilience is often adapted to data availability, research objectives, and system context. Resilience is initially defined as a system’s ability to prepare for and prevent risks through resource planning and allocation, as well as structural and operational adjustments [36,37]. Nevertheless, these definitions have since evolved to encompass not only preparation, but also the capacity to respond to and recover from risks [38,39,40].
Building on these conceptual developments, recent research has increasingly framed resilience as a process-oriented lifecycle rather than a static system property [39,40]. Under this perspective, resilience is operationalised as a sequence of interconnected stages, typically comprising preparation, response, and recovery. One representative example is the Prepare–Act–Recover framework developed for Positioning, Navigation and Timing (PNT) resilience in critical national infrastructure (see Figure 4). This framework structures resilience into governance preparedness, real-time operational action, and post-event recovery and learning phases, thereby translating abstract resilience principles into implementable system requirements.
The Prepare stage emphasises anticipatory capacity and institutional readiness. In this phase, risk management and resilience requirements are embedded into system design and governance structures to ensure that foreseeable threats can be managed within routine operational procedures rather than treated as exceptional crises. System testing, stress analysis, and simulation exercises are conducted to evaluate behavioural responses under threat and risk conditions, thereby identifying latent prevention and mitigation strategies to maintain essential levels of safety, security, and operational performance. The Act and Recover stages address real-time operational response and post-disruption adaptation within a structured lifecycle. During the Act phase, disruption events are detected and diagnosed at the possible stage, thereby activating predefined response mechanisms to preserve critical functions while continuously monitoring system performance. The Recover phase subsequently manages the controlled restoration of operations to normal or stabilised degraded states, ensuring that requirements remain satisfied throughout the transition. This phase also includes systematic evaluation of response effectiveness and mitigation performance. Insights derived from disruption events are integrated into revised contingency plans, governance procedures, and continuity frameworks, thereby institutionalising organisational learning and progressively strengthening long-term resilience.
There is a common consensus on how to define processes of Act and Recover from a disruption (shown in Figure 5). From the time t 0 of focus in the study, between the initial time t 0 and the disruption occurrence time t s , the system function indicator p remains at a stable high level p 0 . At the time t s , the disturbance begins to take effect. Where there is sufficient forethought and the early warning system is fully functioning as a precautionary measure, the system may remain safe, with its performance unaffected, always remaining at p 0 (as shown by the green line in the figure). However, in most cases, the system’s p-value will decline to the system’s minimum functionality p n m i n (n = 2, 3, 4) at time t n 1 (n = 2, 3, 4). Within the time period t n 1 , t n 2 (n = 2, 3, 4), the system may maintain minimum functionality. This indicates that the entire system has achieved a degree of compromise amidst disturbances, thereby enabling operation at low power. At the recovery time t n 2 (n = 2, 3, 4), the system’s resilience begins to exceed the capacity of the shock, and the overall system function (p value) starts to recover. At t n 3 (n = 2, 3, 4), the system once again reaches a relatively steady state. The p value also remains at a stable high level p n (n = 1, 2, 3, 4) for an extended period. It should be emphasised that p 0 and p n (n = 1, 2, 3, 4) are not necessarily identical. In practice, the value of p n (n = 1, 2, 3, 4) may be less than (the blue line in the figure, p 2 < p 0 ), equal to (the yellow line in the figure, p 4 = p 0 ), or even greater (the orange line in the figure, p 3 > p 0 ) than p 0 . Moreover, it is worth noting that the system does not begin to resist the impact at t n 2 (n = 2, 3, 4) (its recovery actions may have already begun at t n 1 (n = 2, 3, 4) or earlier). Still, at t n 1 (n = 2, 3, 4), the system has successfully prevented further functional decline. Additionally, the disturbance is not instantaneous; it may persist after t n 2 (n = 2, 3, 4). However, during the interval t 0 , t n 1 (n = 2, 3, 4), the disturbance’s ‘destructive capacity’ on the p value exceeds the ‘repair capacity’ of the system, while during the interval t n 2 , t n 3 (n = 2, 3, 4), the situation is reversed. Between t n 1 , t n 2 (n = 2, 3, 4) and after t n 3 (n = 2, 3, 4), these two capabilities are roughly balanced, leading to the stability of the p value. In addition, on occasion, the parameter representing the p value may be a ‘negative parameter’. That is, the magnitude of this parameter is positively correlated with the severity of the disturbance. The resilience process image will not be the same as in Figure 5a; rather, it will be the opposite, as shown in Figure 5b. It is worth noting that negative parameters can readily be converted into positive parameters, as shown in Figure 5a, by taking their reciprocals or logarithms.

3.3. Relationship Between Security and Resilience

The concepts of security and resilience are intrinsically linked. In the preceding discussion, security was defined as a state where functionality remains unaffected (i.e., maintained at a high level) despite disturbances. Disturbances that disrupt this secure state may be termed security incidents. Similarly, Figure 5 and Figure 6 depict the resilience process, describing a system’s journey from a steady state through disturbance to recovery. During the time intervals t 0 , t s and t 0 , t e n d , the system’s functionality is maintained at a high level, consistent with this paper’s definition of security. Thus, the system is secure during t 0 , t s and t 0 , t e n d . However, at time t s , a disturbance occurs, disrupting the system’s stability and thereby compromising its secure state. The event occurring at t s may thus be termed a security incident.
Such incidents may yield three distinct consequences of varying severity: no impact on the stability of system functionality; a non-negligible impact on system functionality, yet with the ability to ultimately achieve a new steady state; or a non-negligible impact on system functionality with a failure to achieve a new steady state. To minimise potential losses, the resilience preparation phase must comprehensively define security incidents and design corresponding prevention and response strategies for the action phase when such incidents occur. If a security incident occurs and the system can effectively prevent it, the system’s functionality will not be significantly affected. In this scenario, both p m i n and p 0 in Figure 5 and Figure 6 are greater than or equal to p 0 , indicating that the system remains secure under this security incident. If a security incident occurs and the system cannot effectively prevent it, the system’s functionality will suffer an unignorable impact. If the system can respond effectively, it can ultimately restore functionality. If the system cannot respond effectively, its functionality will suffer irreversible damage. The system is no longer secure under these security incident scenarios, and its ability to return to a secure state after functionality is impacted constitutes the system’s resilience.

4. Airport Structure and Sensor Networks

4.1. Airport Structure

Airports can be divided into landside and airside sections based on their functions and access controls, each comprising specialised facilities and equipment [41,42]. The landside section represents the interface between the airport and external transport networks, covering passenger access, ground transport, and supporting or command functions that enable coordination with airside operations. In contrast, the airside section encompasses the operational domain connected to the surrounding airspace, including aircraft take-off, landing, taxiing, maintenance, and passenger boarding processes [43]. Based on the literature review, we summarised and illustrated the location of airport facilities in Figure 6, and the details of the landside and airside zones are enumerated below:
1.
External transport facilities, or the ground access system, connect the airport with surrounding areas and include public transport infrastructure, road networks, and parking facilities. Although not always directly owned by the airport, transport hubs are increasingly integrated, and the need for seamless transfers has made these facilities operationally interdependent with airport systems [44]. In particular, mutual recognition of security screening requires a high level of interoperability between airport and external transport security systems, making their integration into the airport management framework both necessary and practical.
2.
Connect area is the interface between the external transportation facilities and the terminal buildings. This component broadly encompasses the access roads outside the airport’s terminals.
3.
The terminal building is the core airport facility, enabling passenger processing and the transition between landside and airside operations. It is typically divided into authorised and non-authorised areas. Non-authorised areas are publicly accessible and connected to external transport interfaces, including facilities such as ticketing, baggage check-in, and arrival pick-up [41,42,43,45]. In contrast, authorised areas require controlled access, with multiple levels of authorisation depending on user roles. Some zones are restricted to specific staff through authentication, while others are accessible to passengers only after security screening and validation of boarding credentials.
4.
The control tower is the airport’s command centre and is responsible for coordinating airport operations, controlling airside activities, and handling emergencies. It may also house the main computer room for electronic systems, including communications, surveillance, and navigation.
5.
Non-airport movement areas are those for passenger and staff movements and should be constructed to avoid overlap with aircraft movement areas. These areas may contain boarding gateways and ferries.
6.
Aircraft movement areas are those where aircraft travel on land and where access by personnel is to be avoided. These areas typically include aprons, runways, and manoeuvring areas, and may also include connecting taxiways that facilitate aircraft ground movement and operational linkage between different airside zones.
7.
Ground facilities are the facilities and equipment that service the aircraft and may include ground handling areas (refuelling and loading areas), associated infrastructure (lights, signs and ground support lines), cargo and mail processing, as well as other facilities (hangars, firefighting, water supply, and drainage system).
Facility layouts vary across airports due to design and regulatory differences. For example, baggage claim areas are typically located within authorised zones in Europe, but are often placed in non-authorised areas in the United States. These variations highlight that airport functional zones are not only physical divisions but also define different security boundaries and risk exposure levels.

4.2. Airport Sensor Systems

Sensors are fundamental to airport security and resilience, supporting a wide range of operational functions [46]. In contemporary practice, airport security has evolved from fragmented legacy systems to a cohesive, IP-based “defence-in-depth” architecture, in which sensors are no longer isolated devices but components of an interconnected, cascaded network spanning both physical and digital domains [47,48,49]. This integration ensures that no single point of failure can result in a catastrophic breach, thereby enhancing overall system resilience through multi-layered protection [33,50].
In total, sensors can be classified according to deployment location, including landside (e.g., passenger screening) and airside (e.g., cargo and perimeter monitoring), as well as by configuration (e.g., embedded or surface-mounted), with performance requirements varying significantly depending on operational context [43,51,52,53]. Sensor roles are often overlapping. For instance, a single camera system may simultaneously support passenger behaviour analysis and infrastructure monitoring [54,55]. Similarly, distributed sensor networks are essential for large-scale functions such as perimeter intrusion detection, where no single sensor can provide complete coverage [56,57].
The Transportation Security Laboratory (TSL) of the Department of Homeland Security classifies airport sensor systems into four primary domains based on their functions: commerce inspection, passenger inspection, infrastructure protection, and conveyance protection [56,58]. Commerce and passenger inspection systems focus on screening cargo, baggage, and passengers, typically employing similar sensing technologies such as Radio-Frequency Identification (RFID), X-ray imaging, and Computed Tomography (CT), but differ in deployment scale, spatial distribution, and operational precision due to the separation principle applied in security screening [53,59]. These systems are distributed across airport functional areas, with commerce inspection primarily located in airside cargo and baggage handling facilities. In contrast, passenger inspection is concentrated within terminal departure zones at the landside–airside interface [41,42,43,45]. At this interface, passengers and carry-on baggage are processed through multi-stage screening pipelines, including image-based systems, body scanners, and explosive trace detection, with secondary and random inspections applied to reduce false positives [59,60].
Infrastructure protection systems constitute the first line of defence, focusing on safeguarding critical assets such as perimeters, runways, and restricted zones. These systems typically employ layered sensing mechanisms, including infrared barriers, fibre-optic or taut-wire fence sensors, and buried electromagnetic cables, enabling precise intrusion detection and localisation [55,58,61]. Conveyance protection systems, by contrast, monitor the safety and reliability of internal transport systems and aircraft operations, increasingly using advanced sensing technologies such as 3D LiDAR and thermal imaging to enable continuous surveillance and detection of unauthorised access or safety violations [55,58,61].
A key feature of modern airport sensor architectures is the integration of heterogeneous data streams via system-level platforms, often conceptualised as a Common Operating Picture (COP), in which sensor fusion combines multiple sensing modalities to improve detection accuracy and reduce nuisance alarms caused by environmental disturbances [33,50]. This enhances situational awareness and enables security operators to prioritise genuine threats, thereby improving response efficiency and operational decision-making [27].
Furthermore, advances in Artificial Intelligence (AI) have enabled the incorporation of behavioural analysis and multi-modal sensor synergy into airport security systems. For example, combined thermal and visual sensing enables robust target detection across varying environmental conditions, while AI-driven video analytics supports anomaly detection and behavioural assessment of passenger flows [54,55]. At the same time, the increasing digitalisation of sensor networks introduces cybersecurity considerations, necessitating protective measures such as network segmentation to mitigate risks associated with unauthorised access and lateral movement across interconnected systems [48].
Modern sensor systems increasingly extend beyond traditional security roles to encompass environmental monitoring, passenger well-being, and operational optimisation [62,63]. For example, security screening systems remain comparatively well-defined, focusing on detecting prohibited items by controlling the separation and inspection of passengers and their baggage. Accordingly, an airport security screening system can be defined as a sensor-based, integrated system comprising passenger and baggage inspection components, deployed within terminal departure zones and physically configured to interact directly with passenger flows, while being embedded within a broader, interconnected, and resilient sensor ecosystem [33,59].

5. Airport Threat Landscape: Definitions, Impacts, and Limitations

Airports are inherently exposed to a wide range of multifaceted and evolving threats due to their role as high-density, highly interconnected transportation hubs [28,32]. The concentration of passengers, complex spatial configurations, and extensive stakeholder networks amplify the potential consequences of disruptions, making real-time assessment and coordinated response particularly challenging. In addition to persistent security risks, airports are increasingly exposed to adaptive adversarial behaviours exploiting emerging vulnerabilities in complex, digitalised systems [64,65,66].
These vulnerabilities are further reflected in operational performance and systemic behaviour. Airport security systems must balance stringent safety requirements with efficiency, stability, and the passenger experience, often resulting in trade-offs such as increased layers of screening, resource allocation constraints, and reliance on human judgement [60,67,68]. Meanwhile, digitalisation and smart airport initiatives enhance situational awareness and operational capabilities but also introduce new cyber and data-related risks, including privacy concerns, increased system complexity, and expanded attack surfaces [69,70,71,72,73].
Consequently, airport threats extend beyond conventional, isolated incidents to encompass a broad spectrum of risks, ranging from high-impact physical events to low-level operational disruptions and emerging chemical and digital threats. These risks are not independent; rather, they are embedded within tightly coupled systems and may interact, propagate, and escalate across interconnected domains [74]. We divide threats into 5 categories: cyber, physical, social, environmental, CBR. Within this framework, this section focuses on a set of representative threats and analyses them using a consistent five-component structure, including definition, mechanism, operational impact, mitigation, and limitations.

5.1. Cyber Threats

1.
AI-enabled adversarial attacks on automated security systems exploit machine-learning vulnerabilities in screening, biometric authentication, and threat detection through adversarial examples, data poisoning, and model inversion [75,76,77]. Consequently, compromised AI systems enable undetected breaches, generate excessive false alarms, and erode trust in automated security, potentially forcing reversion to manual processes.
Mitigation measures, including adversarial training, input validation, and ensemble methods, improve robustness but introduce computational overhead and remain vulnerable to adaptive attacks. Trade-offs among accuracy, robustness, and operational speed remain unresolved, with no consensus on acceptable false-positive or false-negative rates in mission-critical applications. In addition, the propagation of adversarial effects across interconnected AI systems is poorly understood, and real-world validation remains constrained by safety and security limitations.
2.
Supply chain compromise of critical airport Information Technology (IT)/Operational Technology (OT) systems involves adversaries infiltrating hardware, software, or firmware during manufacturing, distribution, or maintenance [75,78]. These attacks manifest as backdoors in Supervisory Control and Data Acquisition (SCADA) controllers, compromised biometric firmware, or trojanised updates in air traffic management systems that activate under specific conditions. Consequently, compromised systems enable persistent unauthorised access, data exfiltration, and covert sabotage, bypassing perimeter defences and affecting flight safety, data integrity, and operational continuity.
Mitigation measures, including vendor assessments, code signing, and hardware verification, provide partial protection but are constrained by complex global supply chains with inconsistent security standards. These measures lack methods to assess cumulative risk across multi-tier supply chains, particularly for legacy systems with opaque provenance. Detection of dormant compromises triggered under specific conditions remains unresolved. Moreover, international coordination mechanisms for supply chain security are also fragmented.
3.
Insider- and Outsider-facilitated cyberattacks collectively constitute a critical class of cyber threats targeting airport operations, involving both external attackers and malicious or compromised insiders who exploit system vulnerabilities or use legitimate access [75,78,79]. These threats manifest through techniques such as phishing, unpatched vulnerabilities, insider credential misuse, unauthorised queries, or deliberate system misconfiguration, enabling attackers to encrypt critical data (e.g., flight schedules, passenger manifests, maintenance records), exfiltrate sensitive information, turn off essential systems, or support coordinated external attacks. Consequently, such compromises can bypass perimeter defences and lead to system outages that force a transition to manual operations, resulting in flight disruptions, processing delays, and potential safety risks when critical operational data becomes unavailable, while also enabling covert data theft or manipulation with delayed detection.
Mitigation measures, including backups, network segmentation, endpoint protection, access logging, behavioural analytics, separation of duties, background checks, and incident response planning, aim to enhance resilience but also reveal underlying propagation mechanisms. In particular, ransomware and related attacks spread across interconnected airport systems through lateral movement enabled by shared credentials, insufficient network isolation, and administrative privileges. The increasing digitalisation and interconnection of airport infrastructures—often without a unified or standardised architecture—facilitate rapid propagation across operational, airline, and governmental systems. This interconnectedness further shapes coordination dynamics during cyber incidents, requiring synchronised responses across multiple stakeholders while simultaneously increasing the risk of cascading disruptions.
Nevertheless, significant limitations remain. Backup systems may themselves be compromised during sophisticated ransomware attacks, undermining recovery strategies. Behavioural analytics often suffer from high false-positive rates and limited capability to distinguish malicious intent from legitimate activity, particularly for privileged users or in cases of insider collusion. Moreover, there is a lack of validated models for predicting insider threat likelihood that integrate psychological, organisational, and technical factors. Legal and privacy constraints further restrict the extent of monitoring and data collection in many jurisdictions. In addition, decision-making frameworks regarding ransom payment versus operational disruption remain ethically and legally complex, with limited empirical evidence on recovery timelines, the effectiveness of system restoration, and cascading economic impacts.
4.
Fragmented digitalisation and system integration failures stem from the rapid adoption of digital technologies without a unified architecture, leading to incompatible systems, data silos, and integration vulnerabilities [75,76]. These issues manifest as legacy systems that cannot interface with modern platforms, inconsistent security policies, and cascading failures in which corrupted outputs propagate across systems. Consequently, integration failures lead to data inconsistencies, disruptions in passenger processing, baggage routing errors, and security gaps due to poor information flow, and limit real-time coordination in emergency response.
Mitigation measures, including enterprise architecture frameworks, API standardisation, and middleware solutions, improve interoperability but are costly and disruptive to implement in legacy infrastructure. These measures lack validated methods to assess cumulative security risks arising from integration complexity, particularly emergent vulnerabilities stemming from unexpected system interactions. In addition, the propagation of integration failures across dependent systems remains poorly understood, including how to balance integration benefits against increased attack surfaces, and empirical data on real-world failure modes in operational airports remain limited.
5.
Blockchain and distributed ledger vulnerabilities in airport security arise from the adoption of blockchain for identity management, baggage tracking, and credential verification, exposing risks such as 51% attacks, smart contract flaws, private key compromise, and consensus manipulation [77]. These issues manifest as unauthorised credential issuance, tampered baggage records, and denial-of-service through network flooding. Consequently, compromised systems undermine trust in distributed credentials, create irreversible fraudulent records, and introduce processing delays during verification failures or forks.
Mitigation measures, including permissioned architectures, smart contract verification, and multi-signature schemes, enhance security but increase system complexity and introduce potential centralisation risks. Trade-offs between decentralisation, performance, and security in aviation contexts remain poorly understood, with no consensus on acceptable latency for safety-critical applications. In addition, the cascading impact of blockchain failures across dependent airport systems, as well as recovery from corrupted or forked ledgers, remains underexplored, and real-world deployment data for validation is limited.

5.2. Physical Threats

1.
Drone intrusions involve unauthorised drones entering airport airspace for surveillance, smuggling, or kinetic attacks [75,80]. These threats manifest as small drones evading detection, swarm attacks overwhelming countermeasures, or weaponised drones targeting aircraft and infrastructure. Consequently, intrusions trigger runway closures, flight diversions, and airspace restrictions, with risks of aircraft collisions during take-off or landing and damage to critical assets. Mitigation measures, including radar detection, Radio-Frequency (RF) jamming, net capture, and geofencing, provide partial protection but struggle with small-drone detection and face legal constraints. Detection systems suffer from high false-positive rates (e.g., birds), and reliable, real-time discrimination between malicious and legitimate drones remains unresolved. In addition, optimal response strategies for simultaneous intrusions are poorly understood, and legal frameworks for countermeasures remain inconsistent across jurisdictions, limiting operational effectiveness.
2.
Vehicle-Borne Improvised Explosive Device (VBIED) involves attackers using vehicles loaded with explosives to breach perimeters or target crowded areas [75]. These attacks cause mass casualties, structural damage, and prolonged airport closures, with cascading impacts on regional air transport and potential secondary attacks during evacuation.
Mitigation measures, including standoff distances, vehicle barriers, screening checkpoints, and surveillance, provide protection but must balance security with accessibility for legitimate vehicles. Risk assessment models struggle to account for evolving vehicle types and adaptive attacker tactics. In addition, methods for optimising barrier placement to mitigate both ramming and blast effects while maintaining operational flow remain underdeveloped, as do coordination mechanisms for rapid threat assessment of suspicious vehicles.
3.
Perimeter breaches involve intruders bypassing fencing, gates, or checkpoints to enter restricted airside areas [75,79]. These breaches manifest as fence-cutting, tunnel-digging, credential forgery, or exploitation of maintenance access points, often during shift changes or in adverse weather. Consequently, unauthorised access enables aircraft sabotage, explosive placement, cargo theft, or disruption of ground operations, and delayed detection increases the potential for damage.
Mitigation measures, including physical barriers, Closed-Circuit Television (CCTV), motion sensors, and patrols, provide protection but are challenged by large perimeters and environmental factors such as weather and wildlife. Optimal sensor placement and patrol scheduling for complex perimeters remain unresolved optimisation problems, particularly under resource constraints. In addition, the impact of environmental conditions on sensor performance and adaptive security strategies under degraded conditions is poorly understood, and empirical data on real-world breach patterns remain limited.
4.
Long-range attacks, such as standoff weapons Improvised Explosive Devices (IEDs) in terminals and public areas, represent complementary external and internal attack vectors targeting airport infrastructure and passenger concentrations [75]. These threats manifest through attackers using weapons from outside airport perimeters—exploiting adjacent properties, elevated positions, or mobile platforms with clear line-of-sight—as well as through the placement or carriage of concealed explosive devices within terminals, baggage claim areas, or pre-security zones via luggage, suicide vests, or hidden infrastructure devices. Consequently, such attacks can cause mass casualties, aircraft damage, structural destruction, and panic-driven secondary injuries, as well as significant operational disruptions, prolonged terminal closures, and reduced passenger confidence.
Mitigation measures, including perimeter surveillance, threat detection systems, coordination with law enforcement, behavioural detection, explosive trace detection, canine units, and public-area monitoring, enhance defensive capabilities but also reflect inherent vulnerabilities in airport systems. For example, the open-access design of pre-security areas facilitates IEDs deployment by allowing attackers to blend into normal passenger flows. Moreover, the need to balance security with operational efficiency limits the use of intrusive screening, creating exploitable gaps across both external and internal attack surfaces.
Moreover, significant limitations persist. Comprehensive assessment of all potential standoff positions is resource-intensive and quickly outdated as surrounding environments evolve, and validated models for predicting likely attack locations based on terrain and visibility remain limited. Coordination between airport authorities and external law enforcement is often inconsistent, while balancing open access with effective pre-security screening remains unresolved. In addition, empirical understanding of attacker behaviour is limited, and optimal strategies for screening placement that maximise detection while minimising disruption are not yet well established.

5.3. Social Threats

1.
Malicious, compromised or coerced, and negligent or unintentional insider actions collectively represent a spectrum of insider-related threats in airport environments, arising from individuals with legitimate airside access exploiting privileges either deliberately, under external pressure, or inadvertently [75,79]. Consequently, insider threats bypass perimeter security and screening, enabling high-consequence attacks, criminal activities, or exploitation of system weaknesses, often with delayed detection due to the legitimacy of the insider’s presence and the difficulty of distinguishing malicious intent from normal behaviour.
Mitigation measures, including background checks, random employee screening, access logging, behavioural monitoring, employee assistance programmes, reporting mechanisms, security awareness training, and usable, error-tolerant system design, improve resilience but remain insufficient. Behavioural monitoring struggles to infer malicious intent and often yields high false-positive rates; detecting coercion before exploitation is inherently difficult, and human error persists despite training. Furthermore, predictive models for insider threat risk lack reliability, raise privacy concerns, and lack consensus on acceptable monitoring levels. There is limited understanding of the psychological, organisational, and cognitive factors driving insider threats, particularly under high workload and stress. Organisational cultures that support reporting vulnerabilities without negative consequences remain uncommon, and effective intervention strategies, legal protections for coerced individuals, and robust metrics for evaluating security culture are underdeveloped, highlighting the complexity of managing intentional, coerced, and unintentional insider threats in airport operations.
2.
Social unrest in airport environments refers to passenger-driven disturbances arising from stress, uncertainty, or adverse conditions, including anxiety caused by prolonged delays, congestion, theft incidents, or concerns about severe weather and safety. These situations manifest through heightened emotional responses, such as frustration, panic, or agitation, which may escalate into verbal conflicts, non-compliance with procedures, opportunistic criminal behaviour, or crowd disorder in terminals and boarding areas. Consequently, such disturbances can disrupt passenger flow, degrade service efficiency, increase staff workload, and introduce safety risks, particularly in high-density environments where localised incidents may propagate rapidly through crowds.
Mitigation measures, including real-time information provision, queue management, visible security presence, incident reporting systems, environmental design (e.g., space layout and signage), and staff training in de-escalation, aim to reduce the likelihood and impact of unrest but remain limited in scope. Passenger behaviour is inherently difficult to predict, especially under conditions of uncertainty, fatigue, or perceived loss of control, and current monitoring systems cannot reliably detect early signs of escalation. Furthermore, there is limited understanding of the combined psychological, environmental, and operational factors that trigger unrest, and predictive models of crowd-level behavioural responses remain underdeveloped. Balancing efficient operations with passenger well-being is also challenging, and quantitative metrics to assess emotional states, perceived service quality, and their impact on operational resilience are lacking, highlighting the complexity of managing low-intensity yet high-impact disturbances in airport systems.

5.4. Environmental Threats

1.
Extreme weather events and climate change impacts include severe weather and long-term climate effects that damage infrastructure and disrupt airport operations [81,82,83]. Such events cause flight cancellations, infrastructure degradation, and safety risks, with cascading impacts across regional air networks and prolonged recovery when multiple systems are affected.
Mitigation measures, including infrastructure hardening, drainage systems, backup power, and weather monitoring, improve resilience but are challenged by the increasing frequency and severity of events beyond historical design limits. Predictive models for cascading failures during compound events remain underdeveloped, particularly for interacting hazards such as flooding, power loss, and communication failure. In addition, optimal allocation of resilience investments under uncertain climate futures is poorly understood, methods for assessing vulnerability to novel climate scenarios remain limited, and coordination mechanisms for regional airport resilience during widespread disruptions are underdeveloped.
2.
Seismic events and geological hazards include earthquakes and landslides that damage runways, terminals, and underground infrastructure [81,83]. Such events cause immediate operational shutdowns, extensive structural damage, and cascading failures in fuel, power, and communication networks.
Mitigation measures, including seismic design standards, structural reinforcement, and emergency planning, improve resilience but are constrained by the high costs and disruptions associated with retrofitting existing infrastructure. Understanding of how seismic effects propagate across interconnected systems, particularly under complex soil conditions, remains limited. In addition, validated models for post-earthquake functionality assessment that capture cascading failures are lacking, and optimal strategies for rapid damage assessment and prioritised restoration remain underdeveloped.

5.5. CBR Threats

1.
Pandemic disease outbreaks and infectious disease transmission arise from airports acting as hubs for pathogen spread via infected passengers moving through terminals, aircraft, and destination regions [75]. These processes operate through multiple transmission pathways, including spread in high-density environments, fomite-based surface contamination, and the movement of asymptomatic or pre-symptomatic individuals who evade conventional screening mechanisms. Consequently, pandemics lead to passenger volume collapse, workforce shortages, and operational disruptions due to health control measures, while enabling rapid global transmission.
Mitigation measures, including health screening, ventilation, sanitation protocols, and passenger tracing, improve resilience but vary in effectiveness depending on pathogen characteristics and compliance. Optimal screening strategies that balance detection, throughput, and resource use remain poorly defined, particularly for asymptomatic or long-incubation diseases. In addition, airport-specific transmission models that incorporate passenger flows, contact networks, and environmental factors remain underdeveloped, and legal and privacy barriers constrain international coordination on health standards and data sharing.
2.
Other CBR attacks involve the deployment of chemical, biological, or radiological agents in terminals, ventilation systems, or aircraft [75]. Such incidents cause mass casualties, widespread contamination requiring decontamination, prolonged closures, and significant psychological and economic impacts.
Mitigation measures, including air-quality monitoring, hazmat response teams, and decontamination protocols, improve preparedness but face challenges in detecting novel agents and enabling rapid response. Detection systems for emerging threats lack sufficient sensitivity and specificity for real-time use, often generating disruptive false positives. In addition, validated protocols for rapid triage, decontamination, and evacuation in complex airport environments are limited, and coordination among airport authorities, public health, and emergency services during active events remains underdeveloped.
However, it is important to emphasise that the threats examined in this section primarily represent direct, identifiable, and relatively isolated events. In practice, many of the most severe airport disruptions arise not from single threats, but from complex interactions among multiple hazards and system components. In particular, cascading failures across interdependent systems, coordinated multi-vector cyber–physical attacks, and large-scale systemic disruptions constitute critical classes of compound threats that emerge from the coupling of infrastructure, operations, and human behaviour, and can propagate across domains, amplifying initial disturbances.
Furthermore, systemic vulnerabilities, including regulatory compliance gaps and inconsistent security standards, can exacerbate these risks by creating heterogeneous security postures and misaligning prescribed measures with actual threat conditions. These governance-related factors influence how threats materialise and evolve, often affecting the overall effectiveness of mitigation and response strategies.
While such cross-domain, compound, and systemic threats are not explicitly analysed in this section, their importance is acknowledged within the broader airport risk landscape. Their exclusion reflects a deliberate scoping decision to enable a structured and comparable analysis of individual threat mechanisms. In addition, cross-domain, compound, and systemic threats can be divided into several different types or layers of single threats, namely complex or cascading threats originate from those simple and single threats. Building on the threats identified in this section, the next section will develop a systematic risk assessment framework to evaluate their likelihood, impact, and implications for airport resilience.

6. Airport Risk Assessment

Risk assessment in airport environments is a complex, multi-layered undertaking, reflecting airports’ status as critical national infrastructure and their exposure to diverse threats. Existing approaches are commonly categorised along two principal dimensions: (1) qualitative versus quantitative methodologies, and (2) holistic versus component-based modelling frameworks.
Qualitative approaches rely on expert judgement, structured checklists, and stakeholder workshops. They are particularly useful in early-stage planning or in contexts where empirical data are limited. Quantitative methods, in contrast, employ probabilistic modelling, statistical inference, and simulation techniques to estimate likelihoods and consequences, thereby enabling comparative risk prioritisation and resource allocation [2,84]. In parallel, holistic models examine the airport as an integrated socio-technical system comprising human, technical, and organisational elements. In contrast, component-based approaches focus on specific subsystems such as air traffic control, baggage handling, or passenger terminal operations.
Regulatory bodies, including International Civil Aviation Organization (ICAO) and the Federal Aviation Administration (FAA), incorporate both qualitative and quantitative perspectives in formal guidance. The ICAO Safety Management Manual outlines a structured safety risk management process that integrates qualitative hazard identification with quantitative assessment techniques [2]. Similarly, the FAA Advisory Circular advocates continuous risk monitoring supported by measurable safety indicators and empirical data collection [85]. Collectively, these frameworks emphasise that effective airport risk assessment requires systematic mechanisms linking hazard identification, causal analysis, and performance or functionality evaluation.
Building on this regulatory foundation, this section uses the airport terminal departure zone as a representative case study to examine the applicability, strengths, and limitations of different risk assessment methodologies. Terminal departure areas are complex socio-technical environments in which high-consequence assets, dense passenger flows, and intensive human–technology interactions converge. Screening checkpoints, baggage handling systems, and passenger processing activities form tightly coupled operational domains in which mechanical failures, human errors, cyber vulnerabilities, and deliberate threats may propagate across subsystems, with potentially severe consequences [86,87,88]. In such settings, risk assessment methods must go beyond identifying isolated hazards and also support the analysis of causal pathways, uncertainty, operational dynamics, behavioural responses, and the propagation of consequences across multiple layers. Accordingly, Table 1 provides a systematic comparison of the main approaches discussed in this section, highlighting their representative methods, analytical capabilities, strengths for airport applications, and key limitations.

6.1. Logic-Based Risk Assessment Approaches

Logic-based risk assessment models are well-established, structured methodologies in airport safety and security analysis. They use formal logical representations to decompose hazards, identify causal pathways, and evaluate barrier performance. Key approaches include FTA, ETA, FMEA, and Bow-tie analysis, each offering complementary analytical perspectives.
FTA employs a deductive, top-down structure in which an undesired top event—such as a checkpoint breach or baggage system failure—is decomposed into combinations of basic causal events using Boolean logic [3,4]. This enables the identification of minimal cut sets and quantitative aggregation of failure probabilities when data are available. In contrast, ETA applies a forward logic, starting from an initiating event and mapping alternative success–failure sequences that represent barrier performance and resulting consequences [5,6], supporting scenario-based evaluation of operational and security impacts.
Bow-tie models integrate these perspectives by combining fault trees for upstream causes and event trees for downstream consequences, providing a system-level view of threats, preventive barriers, escalation factors, and end states [89]. Complementarily, FMEA adopts a bottom-up, inductive approach to systematically identify component- or process-level failure modes and prioritise mitigation using severity, occurrence, and detectability metrics. Extensions such as Failure Modes, Effects, and Criticality Analysis (FMECA) address uncertainty and subjectivity in expert scoring [90].
Applied to terminal departure zones, these approaches offer distinct benefits. FTA supports the verification of complex control systems and layered defences by identifying critical combinations of failures. ETA and Bow-tie models enable consequence mapping and performance indicator selection by tracing how barrier degradation affects outcomes. FMEA supports preventive maintenance, early-stage design evaluation, and local process optimisation, including cybersecurity-enhanced variants for terminal IT and screening systems [91]. In practice, these methods are often integrated: FMEA identifies local vulnerabilities, FTA evaluates system-level combinations, and ETA or Bow-tie models assess the severity of consequences and barrier effectiveness of barriers [86,92].
Despite their transparency and communicability, these models have structural limitations in dynamic terminal environments. Tree-based approaches rely on static logic and binary event representations, limiting their ability to capture temporal evolution, multi-state behaviour, and conditional dependencies without modification [93]. ETA often assumes branch independence and requires reliable estimates of barrier performance, which are difficult to obtain in the presence of human variability and adaptive adversaries [94]. Similarly, FMEA is sensitive to subjective scoring and struggles to represent interdependencies and emergent behaviours in tightly coupled systems.

6.2. Probabilistic Risk Assessment Approaches

BN, DBN, and PRA provide capabilities for causal probabilistic reasoning under uncertainty, temporal state-evolution modelling, integrated frequency–consequence analysis, and adversary-centric vulnerability assessment. These features distinguish them from deterministic approaches such as FTA, FMEA, and ETA [7,8,95]. Addressing the limitations of logic-based methods—particularly in handling data sparsity, adaptive adversaries, and real-time evidence fusion—probabilistic approaches have gained increasing prominence in airport security [9,96].
Their adoption is reflected in applications such as terrorist attack prediction, emergency response decision-making, runway safety assessment, and cargo screening analysis. Through belief updating and evidence integration, BN and DBN move risk assessment beyond static models toward adaptive, data-driven frameworks that incorporate new information. This reflects the need for explicit uncertainty quantification, evolving threat anticipation, and prioritisation of countermeasures in modern terminal departure zones [92,97].
Although grouped under probabilistic risk assessment, these methods differ in structure and computation. BN is a directed acyclic graphical model in which nodes represent random variables, and edges encode conditional dependencies via probability tables, thereby supporting diagnostic and predictive inference [7]. DBN extends this by modelling temporal evolution across time slices, enabling filtering, smoothing, and forecasting of system states relevant to threat progression and response [9,96]. PRA integrates scenario identification, frequency estimation, and consequence modelling into unified risk metrics, supporting cost–benefit optimisation and policy comparison [95,97]. These differences have led to hybrid approaches that combine Bayesian inference with PRA-based quantification within integrated frameworks [92,98].
Operationally, each method offers distinct advantages under uncertainty and limited data. BN enables transparent causal inference and sensitivity analysis by combining sparse data with expert judgement to identify key risk drivers [8,98]. DBN provides temporal forecasting for evolving threats and dynamic response scenarios, including terrorist risk estimation, unlawful interference management, and continuous runway risk updates [9,96]. PRA supports scenario comparison and resource allocation through frequency–consequence analysis, enabling trade-offs between security, efficiency, and cost [95,97].
Despite these strengths, limitations remain. BN may scale poorly with increasing network complexity, making inference computationally intensive and probability elicitation resource-demanding and subjective, especially for rare events. DBN intensifies these challenges due to additional temporal data requirements and higher computational costs. PRA may suffer from incomplete scenarios and simplified representations of human and organisational behaviour, limiting its ability to capture interdependencies and emergent effects. Across all methods, challenges include scarce data on rare security events, high development and maintenance costs, and limited validation across diverse airport contexts.

6.3. Operational and Behaviour-Oriented Risk Assessment Approaches

While probabilistic methods such as Bayesian Networks and PRA enable uncertainty quantification and structured scenario comparison, simulation-based approaches complement them by modelling behavioural, temporal, and spatial dynamics in airport environments. Monte Carlo-based PRA has been widely applied to analyse uncertainty in screening processes, equipment reliability, queue performance, and system resilience, including evaluation of equipment failures and alternative lane configurations under stochastic demand [10]. This reflects recognition that static models are insufficient to represent adaptive human behaviour, congestion dynamics, and layout-dependent effects in terminal departure zones, motivating simulation-driven frameworks.
Within this simulation landscape, several paradigms provide complementary representations. Queueing-network models, often combined with Monte Carlo sampling, capture stochastic arrivals, service variability, and network structure to estimate waiting times, queue lengths, and delay variability under uncertain demand [11,12,13]. These are commonly embedded within discrete-event simulation to validate assumptions and assess sensitivity to alarm rates, staffing, and baggage volumes.
Beyond flow-based models, ABM captures behavioural complexity by representing passengers, operators, and attackers as autonomous agents whose interactions generate emergent behaviour. In parallel, pedestrian-dynamics simulators model continuous-space movement, collision avoidance, and crowd-density effects within realistic geometries. Together, these approaches extend risk assessment by representing how local interactions, stochastic processes, and spatial constraints evolve.
Operationally, simulation methods provide key benefits for terminal risk management. Monte Carlo-based PRA and queueing simulations support evaluation of checkpoint robustness under failures, demand surges, and configuration changes, enabling designs that reduce congestion and delay variability while maintaining security [10,12]. Agent-based evacuation and crowd models improve realism by capturing route choice, congestion propagation, and hazard evolution, enabling quantitative evaluation of evacuation performance and adaptive responses. High-fidelity pedestrian tools, such as MassMotion, support the assessment of layout resilience under peak demand, partial closures, and emergencies, generating metrics such as evacuation time, density thresholds, and bottleneck formation [99]. These capabilities support both operational optimisation and strategic design.
Despite these strengths, simulation approaches present challenges. Monte Carlo PRA and queueing models rely on accurate stochastic inputs and failure distributions, which are difficult to obtain for rare or security-sensitive events, and computational demands increase with scenario complexity. Agent-based and pedestrian simulations face calibration and validation challenges due to limited behavioural data, sensitivity to assumptions, and difficulty validating emergent outcomes. High-fidelity spatial models additionally require detailed geometric and movement data, and often prioritise physical dynamics unless integrated with ABM or discrete-event models. Consequently, while simulation improves realism, it increases data requirements, validation effort, and computational burden.

6.4. TVRA

Broadly speaking, the previously mentioned logic-based, probabilistic, operational and behaviour-oriented risk assessment approaches are all methods within Threat–Vulnerability–Risk Assessment [100]. However, Logic-Based Risk Assessment Approaches typically require stringent assumptions that prove difficult to realise in complex real-world applications [6,93]. Furthermore, whilst probabilistic risk assessment approaches can yield specific probability intervals, industrial practice often prioritises the comparative significance of two threats—that is, the relative probabilities of two events [50]. Finally, the trade-off between cost and security remains a critical consideration in practical applications [33]. Some probabilistic risk assessment approaches, or operational and behaviour-oriented risk assessment approaches that demand substantial computational, human, and resource inputs, may consequently see limited industrial adoption. Consequently, the industrial community extensively employs a parameterised TVRA [50]. This methodology involves hierarchically decomposing the steps within the aforementioned security research framework into several more quantifiable sub-parameters. This approach facilitates straightforward computation, offers strong scalability, and readily integrates with other risk analysis methodologies.
The core of the process is the risk equations (Equation (1)). It quantifies and visualises the priority of identified risk points to filter optimisation options, reduce costs, and increase efficiency.
Risk = ( Likelihood × Vulnerability × Impact ) × 100 %
The specific process for the TVRA scheme conforms to the General Security Framework mentioned in Section 3.1. The first step is to confirm security and resilience requirements and identify critical assets. In this paper, critical assets are defined as those associated with the facility/site that are directly or indirectly vital to its performance of its role [41,42,43,45]. While all critical assets affect the operation of a given infrastructure, their impact on its functionality may differ. These differences may involve the severity of the impact, which is difficult to quantify, or they may be categorised as direct or indirect effects on the function. Facilities and equipment whose entire infrastructure cannot function properly after damage are defined as primary critical assets, and facilities/equipment whose damage affects a primary critical asset are referred to as supportive critical assets [50]. Secondly, the threat scenarios should be analysed. Locate which behaviours may threaten critical assets within the infrastructure in the context of the environment or society in which the infrastructure is located. In practice, law enforcement or media case data from the area around the airport are commonly used to identify potential threat scenarios [101]. The third step is to examine the mitigations already in place within the infrastructure. Established mitigations may affect the likelihood of the real damage occurring, the vulnerability of the target critical assets, and the impact of the risk if it occurs, i.e., the three terms in Equation (3). Finally, a risk index should be generated. The risk index is calculated for each critical asset in each threat scenario, which means quantifying likelihood, vulnerability, and impact. The quantified results are then used to assess risk priority and inform the subsequent optimisation of the security system. Furthermore, analysing the risk scores generated by the TVRA may guide subsequent research and programme design.

6.4.1. LF

The Likelihood Factor (LF) assesses the relative likelihood of individual threat scenarios occurring against the Critical Assets and Facility in question. For a particular threat scenario, the LF represents a numeric value calculated as the sum of the following weighted sub-factors:
1.
Target Attractiveness (TA): This sub-factor assesses the relative attractiveness of the Critical Asset for a potential perpetrator. Attractiveness is a judgment-based assessment of several factors: the target’s perceived symbolic value, its strategic or tactical value, the target’s population, and knowledge of the asset/target’s existence.
  • Asset value: This indicator is intended to measure the value or importance of the assets stored by the target or the target itself. When processing TVRA for a site, we can consider its investment and strategic significance.
  • Flow of people: Under the guidance of the conservative principle, a place should be given a score based on whether it is possible to be exposed to mass passenger flow.
  • Knowability: This indicator primarily measures the general public’s understanding of the site or asset.
2.
Historical data/trend (HD): This sub-factor allows us to consider any similar attacks conducted against similar targets or assets in the past.
3.
CAPability (CAP): The level of capability that has been demonstrated to conduct attacks involving the use of the specified threat and/or the capability to amass material and equipment needed to carry out the threat. The purpose of this sub-factor is to measure whether a threat scenario can be implemented at a cost acceptable to the attacker in a given national context.
  • Legal cost: Is it legitimate to possess core tools within the national context?
  • Material cost: If it takes a certain amount of money to implement a malicious act, it can be considered that the material cost in the threat situation is high. This judgment may require empirical, common-sense-based, or subjective evaluation.
  • Time cost: In common sense, better-prepared crimes tend to cause greater harm. However, for an orchestrating attack, the longer the interval between action and implementation, the more likely it is to be discovered in advance. However, in evaluating the likelihood factor, it is sufficient to consider only the relationship between preparation time and attack probability. When the same effect can be achieved, people will always choose a more time-saving method.
  • Personnel cost: This parameter measures whether multiple, experienced, or trained criminals are needed to carry out attacks.
  • Willpower cost: Although a determined attacker can overcome any obstacle, the high cost of illegal acts may still deter some malicious acts.
4.
Target Deterrence (TD): A judgment-based assessment of the likely effectiveness of the inherent site design characteristics in deterring a threat element from undertaking an attack of the kind specified in the threat scenario. In this case, deterrence is broadly defined as deterrence by denial and deterrence through punishment. Deterrence by denial seeks to deter an action by making it infeasible or unlikely to succeed, thereby denying a potential perpetrator the confidence to attain its objectives. Deterrence by punishment is the idea or theory that the threat of punishment will deter people from committing crimes and reduce the probability and/or level of offending. The primary purpose of this factor is to assess whether the facility can prevent or delay malicious behaviour to achieve deterrence.
  • Device deterrence: If a location is equipped with comprehensive security measures, the attacker may abandon the attack or switch targets.
  • Personnel deterrence: In addition to equipment, staff behaviours can provide deterrence.
  • Device Visibility: Although security measures are in place at some locations, their visibility may be insufficient to deter potential attackers. However, to prevent determined attackers from planning cracking plans, some security devices should be intentionally hidden.
  • Resilience deterrence: Sometimes, potential attackers may abandon their plans or shift targets when they see that the impact of their attacks will be eliminated within a short period. Therefore, resilience can sometimes serve as a deterrent.
The final LF for each threat scenario shall be computed as (the weighting factors are from genuine technical reports [50]):
LF = TA × 25 % + HD × 25 % + CAP × 25 % + TD × 25 %

6.4.2. VF

The Vulnerability Factor (VF) reflects the accessibility of the component or location specified in the threat scenario to a potential terrorist/perpetrator. This is a judgment-based assessment of a particular asset’s vulnerability to a threat element, using the attack method specified in the threat scenario. Several factors are considered when assessing the vulnerability factor, including the physical location of the asset (relative to the threat location), line-of-sight of the asset from the threat location, contamination detection measures and baseline security measures implemented to protect the asset.
1.
Location (LO): This sub-factor assesses the asset’s vulnerability based on location and terrain, both within and adjacent to the asset. The score is a judgment-based assessment of several factors: line of sight to the target/asset, terrain features that provide cover, and the terrain’s traversability. The main purpose of this sub-factor is to measure whether an attacker can approach the target at an acceptable cost.
  • Access restriction time: For a site, if it does not restrict access at any time, the risk it faces is quite high. However, imposing strict access restrictions during periods of high customer traffic may reduce efficiency and increase costs.
  • Access authorisation: The severity of authorisation also determines the vulnerability of assets.
  • Access restriction devices and design: This indicator primarily measures the general public’s understanding of the site or asset’s access restrictions.
  • Terrain factors: Even without issues with the equipment or design, terrain can increase vulnerability.
2.
Baseline Measures (BM): This sub-factor examines the existing security measures on site or those currently planned for implementation. In this context, a layer of security comprises the perimeter fence, personnel, intrusion detection systems, security operations procedures, access control, and biometrics.
The final VF for each threat scenario shall be computed as (weighting factors are from genuine technical reports [50]):
VF = LO × 50 % + BM × 50 %

6.4.3. IF

The Impact Factor (IF) reflects the expected impact given the likelihood of the specified threat. The sub-factors are project-specific and determined in collaboration with the client, based on the client’s operations for the project. Sub-factors being assessed are as follows:
1.
Operational Downtime (OD): This sub-factor assesses the impact on the facility’s operation in the event of a successful attack. It takes into account the availability of redundancy for critical assets/equipment, such as power supplies and cooling systems. If there is no redundancy (i.e., a single point of failure), a devastating attack can disrupt the building’s operations.
2.
Facility Downtime (FD): This sub-factor assesses the extent of physical damage sustained by the facility in the event of a successful attack.
3.
Casualties (C): This sub-factor examines the number and severity of casualties and injuries, derived from the total number of people at the Critical Asset and the type of attack.
4.
Reputation (R): This sub-factor looks at the impact on the reputation of the client, the economic well-being of the client, the politics and reputation of the host-nation government, and the social impact affecting the public.
  • The degree of reputation damage: It is difficult to have a quantitative value to represent this parameter fully and accurately. Here, the reduction in passenger flow will be roughly measured.
  • The breadth of reputation damage: This range refers to the geographical scale at which the event occurred, which has had a reputational impact on the site or location, regardless of other parameters.
  • The depth of reputation damage: This parameter measures whether the reputation impact is limited in the site itself or whether the larger organisation behind it will also be implicated.
  • The Recovery Time of Reputation: This parameter is still determined by customer traffic.
5.
Financial Impact (FI): This sub-factor assesses the estimated overall monetary value, including construction costs, replacement costs for systems/equipment, and losses due to operational disruption.
The final IF for each threat scenario shall be computed as (weighting factors are from genuine technical reports [50]):
IF = OD × 20 % + FD × 20 % + C × 20 % + R × 20 % + FI × 20 %

6.4.4. Risk Score

Based on Equations (3)–(6), a final risk score can be derived.
Risk = ( LF × VF × IF ) × 100 %
TVRA possesses significant advantages in security and resilience research. Beyond the comparative strengths outlined above, this methodology also offers several unique benefits over the other three model types. Firstly, it offers clear objectives, enabling targeted research into specific threat scenarios or critical assets, thereby reducing the burden of data collection and analysis [50]. Secondly, beyond facilitating sub-regional or modular studies, the method adheres to a security research framework where each parameter is interdependent. This accounts for mutual protection or exposure between different critical assets, as well as the impact of actual threat scenarios on both the assets themselves and their interrelationships [102]. Moreover, because of the flexibility in defining and quantifying sub-parameters, this methodology can be readily adapted to similar scenarios with minor modifications. Crucially, it offers universality and scalability by enabling the reconstruction of sub-parameter definitions and quantification methods for entirely distinct scenarios using the same procedural framework [103]. Finally, in the current context, where the concept of resilience is increasingly important, some sub-parameters in the TVRA methodology can reflect the system’s resilience to some extent. For example, the sub-parameter BM in VF can reflect the system’s precautions against threats during the prepare stage to help define the change of the system’s functionality, which can be the slope of functionality curve between the time periods t 0 , t s in Figure 5. The sub-parameters in IF can be used as a measure of the system’s performance or functionality (i.e., p value). They can also help measure the system’s ability to recover its functionality, i.e., the slope of the functionality curve between the time period t r , t 0 and the final p 0 .
The limitations of TVRA are also evident. Firstly, this methodology necessitates extensive preliminary investigations. It requires explicit definitions of the composition of critical assets and potential threat scenarios, which may increase resource and time expenditure [101]. Furthermore, although relationships among critical assets have been discussed, the mutual impacts across different threat scenarios are not accounted for. This may lead to some distortion in the risk scores of mutually influencing threat scenarios [102]. However, this impact may prove negligible [50]. Finally, the methodology does not yield precise data, as each sub-parameter is quantified through comparative analysis [50]. Consequently, when employing TVRA for security research, it is advisable to integrate other risk analysis approaches (such as Logic-Based Risk Assessment Approaches, Probabilistic Risk Assessment Approaches or Operational and Behaviour-Oriented Risk Assessment Approaches mentioned above) or complementary analytical methods to calibrate or refine the results [104,105].

6.4.5. Mock TVRA Process and Applications

Based on the critical assets outlined above, the threat scenarios, and the TVRA methodology used for risk assessment, this paper simulates a TVRA process in a simplified context. Firstly, the focus is on security scanning systems deployed within the passenger departure area of an airport terminal. Secondly, the emphasis is on the previously mentioned threat scenarios: Improvised Explosive Device, CBR Attack, Arson, Civil Unrest, Petty Crime, and Burglary (these threats are relatively common, have different levels of impacts and include different types of threats mentioned in Section 5). Drawing on existing data, this simulated TVRA selects a major airport in a large city on China’s southeastern coast as its target (certain details are withheld due to data sensitivity). The simulation aims to compare the performance of the airport’s security scanning systems under six threat scenarios.
The key information for the TVRA encompasses multiple aspects. Foremost is the airport information. The example airport is a single-terminal international airport with an anticipated annual passenger throughput of approximately 20 million. This airport also serves as part of a transport hub, with direct access within the terminal to other transport infrastructure, such as underground and railway stations. The target critical asset (security screening systems) is situated on the second floor above ground, at the junction between the landside and airside areas. It is divided into two non-interconnecting zones: International Departures and Domestic Departures. The domestic departures area features 14 security screening lanes, while the international departures area has 6 lanes. Each lane is equipped with one security gate and one X-ray scanner, supported by dedicated operators, communication equipment, and data processing devices. Secondly, the environmental and contextual background of the example airport should be provided. The airport is situated in a city along China’s southeastern coast. The 2025 Global Terrorism Index ranks China 49th, indicating a low risk of terrorist attacks [106]. Furthermore, Chinese law prohibits citizens from possessing firearms, while most lethal chemical, biological, and explosive agents are classified as controlled substances, with nuclear agents being prohibited.
This paper employs the threat scenario ‘improvised explosive device’ for simulated TVRA analysis as an example. Note that the TVRA methodology should provide specific numerical values for each sub-parameter and the final risk score. However, due to confidentiality requirements, the specific quantification methods and numerical values have been withheld in this simulated TVRA. The numerical values for each sub-parameter will instead be represented by five decreasing levels: High (H for red color), Relatively High (RH for orange color), Medium (M for yellow color), Relatively Low (RL for blue color), and Low (L for green color).
1.
LF
  • TA: This critical asset occupies the sole passageway connecting the landside to the airside, and all passengers must pass through it. Furthermore, an attack on security screening equipment could severely disrupt airport operations. Consequently, it can be concluded that significant passenger flow converges around this critical asset, its existence is widely known, and an attack on this asset holds both strategic and tactical value. The score for this item is High (H).
  • HD: According to the data, there is no record of any artificially manufactured explosions occurring in similar locations within the same city over the past three years. The score for this item is Low (L).
  • CAP: Under Chinese laws and regulations, materials for manufacturing portable explosive device casings are readily available, but higher-grade explosives and detonators are strictly controlled. The score for this item is Relatively Low (RL).
  • As part of the security infrastructure, personnel operating these facilities constitute security staff, enabling rapid response following an incident. The score for this item is Low (L).
2.
VF
  • LO: The critical asset is prominently located, with signage clearly indicating its position within the airport premises. Furthermore, the route from the airport entrance to this critical asset is unobstructed. The score for this item is High (H).
  • BM: At the example airport, passengers must undergo anti-terrorism screening using test strips at the airport entrance before approaching this critical asset. Furthermore, the facility at the example airport is protected by multiple layers of security equipment (camera surveillance cameras, security patrols, and other anti-terrorism devices). The score for this item is Low (L).
3.
IF
  • OD: Generally speaking, improvised explosive devices can only disrupt one of several security screening lines, thus only partially affecting airport operations. The score for this item is Relatively Low (RL).
  • FD: Whilst unable to compromise the entire security screening system, portable explosive devices can inflict severe damage upon their direct targets. The score for this item is relatively Moderate (M).
  • C: The explosive power of an improvised explosive device is sufficient to cause death. The score for this item is High (H).
  • R: A successful attack on this critical asset through multiple layers of defences using a portable explosive device would cause significant damage to the airport’s reputation. The score for this item is Relatively High (RH).
  • FI: Improvised explosive devices may cause damage to equipment, casualties, and a sharp decline in passenger numbers. However, such impacts would not persist for long at the example airport. The score for this item is Relatively High (RH).
Following the aforementioned procedure to score the remaining five example threat scenarios, the simulated TVRA results are presented in a simple, common-sense analysis, the most vulnerable threat scenario for the security scanning system, under the assumptions of this paper, under the assumptions of this paper is arson (Figure 7). Similarly, applying the TVRA method to different critical assets within the same threat scenario can identify which assets are relatively more vulnerable to that threat.
Beyond comparative prioritisation, the simulated TVRA outputs provide a structured basis for resilience enhancement. By identifying which threat–asset combinations yield the highest composite risk scores, decision-makers can allocate mitigation resources more effectively, thereby strengthening absorptive capacity within the most exposed subsystems. In the context of terminal departure zones, this may involve reinforcing redundancy in screening equipment, enhancing staff training, or improving emergency response coordination for the most critical threat scenarios. In this sense, TVRA supports the “Prepare” dimension of resilience by informing pre-disruption investment and capability planning.
Furthermore, risk score differentiation across threat scenarios and sub-parameters enables more granular analysis of system vulnerabilities and recovery dependencies. For example, identifying that certain scenarios produce high casualty impact but limited operational downtime. In contrast, others cause moderate physical damage yet prolonged functional disruption, allowing planners to distinguish between robustness-oriented and recovery-oriented mitigation strategies. Such differentiation supports the design of layered defensive architectures and contingency plans that reduce performance degradation and shorten recovery time, thereby strengthening both adaptive capacity and recovery performance.
Finally, although TVRA itself is primarily static and comparative, its structured outputs can serve as calibrated inputs for more dynamic resilience modelling frameworks, including simulation-based or digital-twin approaches. By translating risk scores into parameterised stress conditions or scenario weights, resilience analysis can move beyond qualitative prioritisation toward time-dependent performance evaluation under disruption. In this way, the integration of TVRA outputs with dynamic system modelling bridges traditional security risk assessment and resilience-oriented lifecycle management, enabling more informed and proactive decision-making in complex airport environments. Specifically, in various industrial scenarios, methods similar to TVRA have already been widely adopted. Prior to introducing dynamic models, the TVRA method can be used for preliminary analysis to identify key research areas and focus points, thereby helping to guide more targeted data collection and model development. During the dynamic analysis process, TVRA can be used to perform targeted analyses at key spatial or temporal points to obtain more precise results. Alternatively, it can analyse several key points to quantify changes in the system. Following the dynamic analysis process, TVRA can also serve as a means of quantitative analysis to verify or support the results of the dynamic analysis.

7. Conclusions

This study provides a structured review of airport security and resilience analysis, aiming to integrate conceptual frameworks, airport structure, sensor networks, threat characteristics, and risk assessment methodologies.
From a conceptual perspective, the review clarifies the relationship between security and resilience within a lifecycle-oriented framework, highlighting the transition from prevention-focused approaches to an integrated prepare–act–recover architecture. From a structural perspective, this study characterises airport systems as highly interconnected socio-technical environments in which landside and airside components define critical assets, operational dependencies, and system boundaries. Moreover, sensor networks are considered as integrated, multi-layered architectures that support data fusion, situational awareness, and system-wide monitoring.
Airport threats are classified into the cyber, physical, social, environmental, and CBR domains, with their mechanisms, impacts, mitigation strategies, and inherent limitations critically examined. This classification highlights the multi-domain and interdependent nature of airport threats, as well as their potential to propagate across tightly coupled systems.
Existing risk assessment approaches, including logic-based, probabilistic, and operational and behaviour-oriented models, are comparatively analysed, demonstrating their respective strengths in structured reasoning, uncertainty quantification, and dynamic process representation, while also revealing limitations in scalability, data dependency, and real-time applicability.
Furthermore, TVRA offers significant potential as a bridging mechanism between traditional risk assessment and resilience-oriented system design. By translating static risk scores into scenario-based inputs, it can support the development of stress-testing frameworks and inform resilience planning across the prepare, act, and recover phases. However, its inherently static structure limits its ability to capture temporal dynamics and cascading interdependencies, underscoring the need to integrate it with dynamic modelling approaches such as simulation and digital twins.
Several limitations should be acknowledged. First, this study adopts a narrative review methodology rather than a fully systematic review protocol. While appropriate for an interdisciplinary topic spanning academic literature, regulatory guidance, technical reports, industrial practice, and the grey literature, this approach does not claim exhaustive coverage. Source selection and interpretation are therefore shaped by thematic relevance, methodological applicability, and author judgment. In addition, detailed airport threat assessments, vulnerability analyses, and incident-response procedures are often restricted due to security or commercial sensitivity, limiting the extent to which some operational assumptions can be independently validated.
Second, the proposed framework should be interpreted as a transferable analytical foundation rather than a universally fixed model. Airports differ in layout, scale, regulation, sensor deployment, threat exposure, and response capability. Therefore, the asset map, threat landscape, and TVRA-based risk structure require local calibration before implementation. Moreover, although TVRA supports structured expert judgement and threat/asset prioritisation, its outputs remain sensitive to scoring scales, weighting factors, data quality, and expert assumptions. The illustrative TVRA example is therefore intended to demonstrate the method rather than provide a validated operational risk score.
Future research should develop integrated, system-level frameworks that combine structured risk assessment with dynamic modelling to capture temporal evolution, cascading interdependencies, adaptive threats, and recovery processes. This requires real-world operational data, expert elicitation, and airport-specific case studies to calibrate and validate asset classifications, threat scenarios, vulnerability indicators, and resilience metrics. Integrating TVRA with simulation, probabilistic modelling, and digital twins offers a promising pathway from static prioritisation towards real-time monitoring, stress testing, predictive analytics, and adaptive decision-making.

Funding

This research received no external funding.

Data Availability Statement

No new data were created or analysed in this study.

Conflicts of Interest

The authors declare no conflicts of interest.

References

  1. National Protective Security Authority. Critical National Infrastructure. 2024. Available online: https://www.npsa.gov.uk/about-npsa/critical-national-infrastructure (accessed on 27 April 2026).
  2. ICAO. Safety Management Manual (Doc 9859); International Civil Aviation Organization: Montreal, QC, Canada, 2018. [Google Scholar]
  3. Eisen, N.D. Systems Theoretic Process Analysis as a Practical Tool for Comprehensive Flight Test Hazard Identification. Ph.D. Thesis, Massachusetts Institute of Technology, Cambridge, MA, USA, 2024. [Google Scholar]
  4. Kornecki, A.J.; Liu, M. Fault tree analysis for safety/security verification in aviation software. Electronics 2013, 2, 41–56. [Google Scholar] [CrossRef] [Scilit]
  5. Chen, M.; Chen, Y.; Ma, S. Identifying safety performance indicators for risk assessment in civil aviation. In Proceedings of the IOP Conference Series: Materials Science and Engineering; IOP Publishing: Bristol, UK, 2021; Volume 1043, p. 032010. [Google Scholar]
  6. Nikolaev, A.G.; Lee, A.J.; Jacobson, S.H. Optimal aviation security screening strategies with dynamic passenger risk updates. IEEE Trans. Intell. Transp. Syst. 2011, 13, 203–212. [Google Scholar] [CrossRef] [Scilit]
  7. Fenton, N.; Neil, M. Risk Assessment and Decision Analysis with Bayesian Networks; CRC Press: Boca Raton, FL, USA, 2018. [Google Scholar]
  8. Roelen, A.; Wever, R.; Hale, A.; Goossens, L.; Cooke, R.; Lopuhaä, R.; Simons, M.; Valk, P. Causal modeling using Bayesian belief nets for integrated safety at airports. Risk Decis. Policy 2004, 9, 207–222. [Google Scholar] [CrossRef] [Scilit]
  9. Wu, Y.; He, S.; Shi, J. A dynamic decision-making approach for cabin unlawful interference emergency disposal using dynamic Bayesian network. Sci. Rep. 2024, 14, 19002. [Google Scholar] [CrossRef] [Scilit]
  10. Tantai, X. The analysis and optimization of passenger security process of terminal based on Monte Carlo model. In Proceedings of the 2017 2nd International Conference on Materials Science, Machinery and Energy Engineering (MSMEE 2017); Atlantis Press: Dordrecht, The Netherlands, 2017; pp. 420–423. [Google Scholar]
  11. Wang, X.; Song, C.; Zhuang, J. Simulating a multi-stage screening network: A queueing theory and game theory application. In Game Theoretic Analysis of Congestion, Safety and Security: Networks, Air Traffic and Emergency Departments; Springer: Cham, Switzerland, 2015; pp. 55–80. [Google Scholar]
  12. Wang, Y.; Meng, F.; Wang, X.; Xie, C. Optimizing the passenger flow for airport security check. arXiv 2023, arXiv:2312.05259. [Google Scholar] [CrossRef] [Scilit]
  13. Laskey, K.B.; Xu, N.; Chen, C.H. Propagation of delays in the national airspace system. arXiv 2012, arXiv:1206.6859. [Google Scholar] [CrossRef] [Scilit]
  14. Rossi, R.; Gastaldi, M.; Orsini, F. Systematic literature review X narrative review. Acta Paul. Enferm. 2007, 20, v–vi. [Google Scholar]
  15. Tricco, A.C.; Lillie, E.; Zarin, W.; O’Brien, K.K.; Colquhoun, H.; Levac, D.; Moher, D.; Peters, M.D.; Horsley, T.; Weeks, L.; et al. PRISMA extension for scoping reviews (PRISMA-ScR): Checklist and explanation. Ann. Intern. Med. 2018, 169, 467–473. [Google Scholar] [CrossRef] [Scilit]
  16. Page, M.J.; McKenzie, J.E.; Bossuyt, P.M.; Boutron, I.; Hoffmann, T.C.; Mulrow, C.D.; Shamseer, L.; Tetzlaff, J.M.; Akl, E.A.; Brennan, S.E.; et al. The PRISMA 2020 statement: An updated guideline for reporting systematic reviews. BMJ 2021, 372, n71. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  17. Bernardo, W.M.; Nobre, M.R.C.; Jatene, F.B. A prática clínica baseada em evidências: Parte II-buscando as evidências em fontes de informação. Rev. Bras. Reumatol. 2004, 44, 403–409. [Google Scholar] [CrossRef] [Scilit]
  18. Pae, C.U. Why systematic review rather than narrative review? Psychiatry Investig. 2015, 12, 417. [Google Scholar] [CrossRef] [Scilit]
  19. Long, F.; Majumdar, A. Casualty Behaviour and Mass Decontamination: A Narrative Literature Review. Urban Sci. 2025, 9, 283. [Google Scholar] [CrossRef] [Scilit]
  20. Corlett, S.; Mavin, S. Reflexivity and researcher positionality. In The SAGE Handbook of Qualitative Business and Management Research Methods; Sage: London, UK, 2018; pp. 377–399. [Google Scholar]
  21. Cribbin, T.F. Citation chain aggregation: An interaction model to support citation cycling. In Proceedings of the 20th ACM International Conference on Information and Knowledge Management, Glasgow, Scotland, UK, 24–28 October 2011; pp. 2149–2152. [Google Scholar]
  22. Lecy, J.D.; Beatty, K.E. Representative literature reviews using constrained snowball sampling and citation network analysis. SSRN Electron. J. 2012. [Google Scholar] [CrossRef] [Scilit]
  23. Baldwin, D.A. The Concept of Security. In National and International Security; Routledge: London, UK, 2018; pp. 41–62. [Google Scholar]
  24. Craighead, G. High-Rise Security and Fire Life Safety; Butterworth-Heinemann: Boston, MA, USA, 2009. [Google Scholar]
  25. Post, R.S.; Kingsbury, A.A.; Schachtsiek, D.A. Security Administration: An Introduction to the Protective Services; Butterworth-Heinemann: Boston, MA, USA, 1991. [Google Scholar]
  26. Paté-Cornell, E. Risk and uncertainty analysis in government safety decisions. Risk Anal. 2002, 22, 633–646. [Google Scholar] [CrossRef] [Scilit]
  27. Nisula, J.M. A Risk Management Framework for a Complex Adaptive Transport System. Ph.D. Thesis, Université Paul Sabatier–Toulouse III, Toulouse, France, 2018. [Google Scholar]
  28. Cox, A.; Prager, F.; Rose, A. Transportation security and the role of resilience: A foundation for operational metrics. Transp. Policy 2011, 18, 307–317. [Google Scholar] [CrossRef] [Scilit]
  29. Grabo, C.M. Anticipating Surprise: Analysis for Strategic Warning; Center for Strategic Intelligence Research, Joint Military Intelligence College: Bethesda, MD, USA, 2002. [Google Scholar]
  30. Wolfers, A. “National Security” as an Ambiguous Symbol. Political Sci. Q. 1952, 67, 481–502. [Google Scholar] [CrossRef] [Scilit]
  31. Thekdi, S.; Aven, T. An enhanced data-analytic framework for integrating risk management and performance management. Reliab. Eng. Syst. Saf. 2016, 156, 277–287. [Google Scholar] [CrossRef] [Scilit]
  32. Meyer, M.D. The Nation’s Transportation System as a Security Challenge. In Wiley Handbook of Science and Technology for Homeland Security; John Wiley & Sons: Hoboken, NJ, USA, 2008; pp. 1–22. [Google Scholar]
  33. Paté-Cornell, E.; Cox, L.A. Improving risk management: From lame excuses to principled practice. Risk Anal. 2014, 34, 1228–1239. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  34. Stergiou, C.; Psannis, K.E.; Gupta, B.B.; Ishibashi, Y. Security, privacy & efficiency of sustainable cloud computing for big data & IoT. Sustain. Comput. Inform. Syst. 2018, 19, 174–184. [Google Scholar]
  35. Metzner, N. A comparison of agent-based and discrete event simulation for assessing airport terminal resilience. Transp. Res. Procedia 2019, 43, 209–218. [Google Scholar] [CrossRef] [Scilit]
  36. Wang, Y.; Zhan, J.; Xu, X.; Li, L.; Chen, P. Measuring the resilience of an airport network. Chin. J. Aeronaut. 2019, 32, 2694–2705. [Google Scholar] [CrossRef] [Scilit]
  37. Hosseini, S.; Barker, K.; Ramirez-Marquez, J.E. A review of definitions and measures of system resilience. Reliab. Eng. Syst. Saf. 2016, 145, 47–61. [Google Scholar] [CrossRef] [Scilit]
  38. Nan, C.; Sansavini, G. A quantitative method for assessing resilience of interdependent infrastructures. Reliab. Eng. Syst. Saf. 2017, 157, 35–53. [Google Scholar] [CrossRef] [Scilit]
  39. Royal Institute of Navigation. Three Stages for Achieving PNT Resilience in Critical National Infrastructure. 2024. Available online: https://rin.org.uk/mpage/Resilient_PNT_Best_Practices (accessed on 27 April 2026).
  40. Proctor, A.; Andy, R. A Structured Approach to Achieving System Resilience for Position Navigation and Timing (PNT) Systems (PNT System Resilience). ReThink PNT. 2024. Available online: https://rethinkpnt.com/wp-content/uploads/2022/09/Website_copy_PNT-System-Resilience-two-column.pdf (accessed on 27 April 2026).
  41. Janic, M. Air Transport System Analysis and Modelling; CRC Press: Boca Raton, FL, USA, 2000. [Google Scholar]
  42. Horonjeff, R.; McKelvey, F.X.; Sproule, W.J.; Young, S.B. Planning and Design of Airports, 5th ed.; McGraw-Hill: New York, NY, USA, 2010. [Google Scholar]
  43. Wilke, S. Modelling Airport Surface Safety: A Framework for a Holistic Airport Safety Management. Ph.D. Thesis, Imperial College London, London, UK, 2014. [Google Scholar]
  44. Meng, Y.; Liu, D.; Rong, W.; Wu, M. Security Check Mutual Recognition between High-Speed Railway and Urban Rail Transit Based on Variable Fuzzy Set Theory. Math. Probl. Eng. 2022, 2022, 6571007. [Google Scholar] [CrossRef] [Scilit]
  45. Crosby, M.; Steinle, M.; Nobel, K.; Smith, T. Airport Security Vulnerability Assessments; Technical Report; National Safe Skies Alliance, Inc.: Louisville, TN, USA, 2020. [Google Scholar]
  46. de Neufville, R. Airport Systems Planning, Design, and Management. In Air Transport Management; Routledge: New York, NY, USA, 2020; pp. 79–96. [Google Scholar]
  47. Li, Y.; Gao, X.; Xu, Z.; Zhou, X. Network-Based Queuing Model for Simulating Passenger Throughput at an Airport Security Checkpoint. J. Air Transp. Manag. 2018, 66, 13–24. [Google Scholar] [CrossRef] [Scilit]
  48. Nayeem, M.H.; Moradi, S.; Hossain, N.U.I.; Shamsuddoha, M.; Islam, M.S. System Dynamics Modeling for Assessing Operational Performance of an Airport Terminal. Case Stud. Transp. Policy 2025, 19, 101345. [Google Scholar] [CrossRef] [Scilit]
  49. Pan, Y.; Zhang, X.; Xu, Q.; Liu, H. Reducing Waiting Time at an Airport Security Checkpoint Based on the Queuing Model. In Proceedings of the 2019 IEEE Chinese Control and Decision Conference (CCDC), Nanchang, China, 3–5 June 2019; pp. 3860–3865. [Google Scholar]
  50. ARUP. Gasan Data Centre Threat Vulnerability & Risk Assessment; Technical Report; ARUP: London, UK, 2023. [Google Scholar]
  51. Dong, M.; Hayhoe, G.F. Denver International Airport Sensor Processing and Database; Technical Report DOT/FAA/AR-00/17; United States Federal Aviation Administration, Office of Aviation Research: Washington DC, USA, 2000. [Google Scholar]
  52. Kazda, A.; Caves, R.E. (Eds.) Airport Design and Operation; Emerald Group Publishing Limited: Leeds, UK, 2010. [Google Scholar]
  53. Young, S.; Wells, A.T. Airport Planning & Management, 7th ed.; McGraw Hill LLC: New York, NY, USA, 2019. [Google Scholar]
  54. Siddiqui, F.M. Designing Airport Terminal New Facilities by Exploiting Parallel Intelligence and Level of Service Framework. In Proceedings of the 2025 IEEE Integrated Communications, Navigation and Surveillance Conference (ICNS), Brussels, Belgium, 8–10 April 2025; pp. 1–6. [Google Scholar]
  55. Cui, J.; Wang, X.; Li, X.; Liu, Y.; Ba, P.; Xu, C.; Chyży, T. Design and Implementation of Health Monitoring System for an Airport Terminal Building with a Large-Span Truss Steel Structure. Buildings 2025, 15, 3308. [Google Scholar] [CrossRef] [Scilit]
  56. Davis, A.; Chang, H. Airport Protection Using Wireless Sensor Networks. In Proceedings of the 2012 IEEE Conference on Technologies for Homeland Security (HST), Waltham, MA, USA, 13–15 November 2012; pp. 36–42. [Google Scholar]
  57. Shan, J.; Miccinesi, L.; Beni, A.; Pagnini, L.; Cioncolini, A.; Pieraccini, M. A Review of Foreign Object Debris Detection on Airport Runways: Sensors and Algorithms. Remote Sens. 2025, 17, 225. [Google Scholar] [CrossRef] [Scilit]
  58. Hallowell, S.F.; Jankowski, P.Z. Transportation Security Technologies Research and Development. In Proceedings of the MILCOM 2005–2005 IEEE Military Communications Conference, Atlantic City, NJ, USA, 7–20 October 2005; pp. 1753–1756. [Google Scholar]
  59. Raja, M.F.; Sutarwati, S. Reconciliation Analysis of Passengers Suspected of Carrying Dangerous and Prohibited Goods at Komodo Labuan Bajo Airport Security Checkpoint. QISTINA J. Multidisiplin Indones. 2023, 2, 317–325. [Google Scholar] [CrossRef] [Scilit]
  60. van Boekhold, J.; Faghri, A.; Li, M. Evaluating security screening checkpoints for domestic flights using a general microscopic simulation model. J. Transp. Secur. 2014, 7, 45–67. [Google Scholar] [CrossRef] [Scilit]
  61. Lykou, G.; Moustakas, D.; Gritzalis, D. Defending Airports from UAS: A Survey on Cyber-Attacks and Counter-Drone Sensing Technologies. Sensors 2020, 20, 3537. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  62. Airports Council International. Guide to Airport Performance Measures; Technical Report; Airports Council International: Montreal, QC, Canada, 2012. [Google Scholar]
  63. Zanni, S.; Lalli, F.; Foschi, E.; Bonoli, A.; Mantecchini, L. Indoor Air Quality Real-Time Monitoring in Airport Terminal Areas: An Opportunity for Sustainable Management of Micro-Climatic Parameters. Sensors 2018, 18, 3798. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  64. Air Transport Action Group. Facts and Figures. 2024. Available online: https://atag.org/facts-figures (accessed on 27 April 2026).
  65. Global Terrorism Database (GTD). Advanced Search by Years: (Between 1971 and 2020) and Targets: (Airports and Aircraft). 2024. Available online: https://www.start.umd.edu/data-tools/GTD (accessed on 27 April 2026).
  66. Mujica Mota, M.; Scala, P.; Delahaye, D. Improving Airport Performance Through a Model-Based Analysis and Optimization Approach. In Applied Simulation and Optimization 2; Springer International Publishing: Cham, Switzerland, 2017; pp. 109–129. [Google Scholar]
  67. de Lange, R.; Samoilovich, I.; van Der Rhee, B. Virtual queuing at airport security lanes. Eur. J. Oper. Res. 2013, 225, 153–165. [Google Scholar] [CrossRef] [Scilit]
  68. Welch, J.D.; Cho, J.Y.; Underhill, N.K.; DeLaura, R.A. Sector workload model for benefits analysis and convective weather capacity prediction. In Proceedings of the Tenth USA/Europe Air Traffic Management Research and Development Seminar (ATM2013), Chicago, IL, USA, 10–13 June 2013. [Google Scholar]
  69. Agarwal, R.; Gao, G.; DesRoches, C.; Jha, A.K. Research commentary—The digital transformation of healthcare: Current status and the road ahead. Inf. Syst. Res. 2010, 21, 796–809. [Google Scholar] [CrossRef] [Scilit]
  70. Braun, T.; Fung, B.C.; Iqbal, F.; Shah, B. Security and privacy challenges in smart cities. Sustain. Cities Soc. 2018, 39, 499–507. [Google Scholar] [CrossRef] [Scilit]
  71. Nau, J.B.; Benoit, F. Smart Airport: How Technology is Shaping the Future of Airports; Wavestone: Paris, France, 2017. [Google Scholar]
  72. Alabsi, M.I.; Gill, A.Q. A review of passenger digital information privacy concerns in smart airports. IEEE Access 2021, 9, 33769–33781. [Google Scholar] [CrossRef] [Scilit]
  73. Thums, J.; Künzel, L.; Klumpp, M.; Bardmann, M.M.; Ruiner, C. Future air transportation and digital work at airports–Review and developments. Transp. Res. Interdiscip. Perspect. 2023, 19, 100808. [Google Scholar] [CrossRef] [Scilit]
  74. Aven, T.; Krohn, B.S. A new perspective on how to understand, assess and manage risk and the unforeseen. Reliab. Eng. Syst. Saf. 2014, 121, 1–10. [Google Scholar] [CrossRef] [Scilit]
  75. Koroniotis, N.; Moustafa, N.; Schiliro, F.; Gauravaram, P.; Janicke, H. A holistic review of cybersecurity and reliability perspectives in smart airports. IEEE Access 2020, 8, 209802–209834. [Google Scholar] [CrossRef] [Scilit]
  76. Zaharia, S.E.; Pietreanu, C.V. Challenges in airport digital transformation. Transp. Res. Procedia 2018, 35, 90–99. [Google Scholar] [CrossRef] [Scilit]
  77. Koepsel, K.M. Commercial Aviation and Cyber Security: A Critical Intersection; SAE International: Warrendale, PA, USA, 2016. [Google Scholar]
  78. Elmarady, A.A.; Rahouma, K. Studying cybersecurity in civil aviation, including developing and applying aviation cybersecurity risk assessment. IEEE Access 2021, 9, 143997–144016. [Google Scholar] [CrossRef] [Scilit]
  79. Bloom, R. Airport Security. In International Encyclopedia of Transportation; Elsevier: Amsterdam, The Netherlands, 2021. [Google Scholar]
  80. Pascarella, D.; Gigante, G.; Vozella, A.; Sodano, M.; Ippolito, M.; Bieber, P.; Dubot, T.; Martinavarro, E. Evaluation of a resilience-driven operational concept to manage drone intrusions in airports. Information 2023, 14, 239. [Google Scholar] [CrossRef] [Scilit]
  81. Köpke, C.; Srivastava, K.; Miller, N.; Branchini, E. Resilience quantification for critical infrastructure: Exemplified for airport operations. In Proceedings of the European Symposium on Research in Computer Security; Springer: Cham, Switzerland, 2021; pp. 451–460. [Google Scholar]
  82. Horton, R.; Trump, B.D.; Trump, J.; Knowles, H.S.; Linkov, I.; Jones, P.; Kiker, G. Performance metrics for resilience of airport infrastructure. Transp. Res. Part Transp. Environ. 2025, 142, 104676. [Google Scholar] [CrossRef] [Scilit]
  83. Janić, M. Analysing and modelling airport resilience: Robustness, vulnerability and recoverability. J. Airpt. Manag. 2021, 15, 361–389. [Google Scholar] [CrossRef] [Scilit]
  84. Du, S.; Zhong, G.; Wang, F.; Pang, B.; Zhang, H.; Jiao, Q. Safety risk modelling and assessment of civil unmanned aircraft system operations: A comprehensive review. Drones 2024, 8, 354. [Google Scholar] [CrossRef] [Scilit]
  85. Federal Aviation Administration. Advisory Circular 150/5200-37A: Introduction to Safety Management Systems (SMS) for Airport Operators; Advisory Circular AC 150/5200-37A; U.S. Department of Transportation, Federal Aviation Administration: Washington, DC, USA, 2007. [Google Scholar]
  86. de Barros, A.G.; Tomber, D.D. Quantitative analysis of passenger and baggage security screening at airports. J. Adv. Transp. 2007, 41, 171–193. [Google Scholar] [CrossRef] [Scilit]
  87. Coman, C.; Dobrescu, L.; Ruscă, F.; Bădău, F. A Systems Engineering Approach to Modeling Reliability and Vulnerability in Automated Airport Baggage Networks. In Proceedings of the 2025 IEEE 17th International Conference on Electronics, Computers and Artificial Intelligence (ECAI), Targoviste, Romania, 26–27 June 2025; pp. 1–5. [Google Scholar]
  88. Stef, J.; Alexei, S.; Richard, C. AbSRiM: An Agent-Based Security Risk Management Approach for Airport Operations. Risk Anal. Off. Publ. Soc. Risk Anal. 2019, 39, 1582–1596. [Google Scholar]
  89. Omidvar, M.; Zarei, E.; Ramavandi, B. The Bow-Tie Method: A Hybrid System Safety and Risk Analysis Approach for Safety–Critical Sociotechnical Systems. In Safety Causation Analysis in Sociotechnical Systems: Advanced Models and Techniques; Springer: Cham, Switzerland, 2024; pp. 123–149. [Google Scholar]
  90. Feng, C.M.; Chung, C.C. Assessing the Risks of Airport Airside through the Fuzzy Logic-Based Failure Modes, Effect, and Criticality Analysis. Math. Probl. Eng. 2013, 2013, 239523. [Google Scholar] [CrossRef] [Scilit]
  91. Balboena Bregalda, M. FMEA Application to Ensure Cybersecurity of Technical Products. Ph.D. Thesis, Technische Universität Wien, Wien, Austria, 2023. [Google Scholar]
  92. Janssen, S.; Sharpanskykh, A.; Curran, R. Agent-based modelling and analysis of security and efficiency in airport terminals. Transp. Res. Part Emerg. Technol. 2019, 100, 142–160. [Google Scholar] [CrossRef] [Scilit]
  93. Zhao, W.; Alam, S.; Abbass, H.A. Evaluating ground–air network vulnerabilities in an integrated terminal maneuvering area using co-evolutionary computational red teaming. Transp. Res. Part Emerg. Technol. 2013, 29, 32–54. [Google Scholar] [CrossRef] [Scilit]
  94. Linero, A.R. A review of tree-based Bayesian methods. Commun. Stat. Appl. Methods 2017, 24, 543–559. [Google Scholar] [CrossRef] [Scilit]
  95. Jha, M.K. Dynamic Bayesian network for predicting the likelihood of a terrorist attack at critical transportation infrastructure facilities. J. Infrastruct. Syst. 2009, 15, 31–39. [Google Scholar] [CrossRef] [Scilit]
  96. Natalia, Y.A.; De Cauwer, H.; Neyens, T.; Goniewicz, K.; Somville, F.; Molenberghs, G. A Bayesian network analysis of aviation terrorism attack risks. J. Transp. Secur. 2025, 18, 19. [Google Scholar] [CrossRef] [Scilit]
  97. Jha, M.K. Applying Bayesian networks to assess vulnerability of critical transportation infrastructure. In Applications of Advanced Technology in Transportation; American Society of Civil Engineers: Reston, VA, USA, 2006; pp. 1–6. [Google Scholar]
  98. Zhou, X.; Liang, W.; Wang, H. Safety Risk Analysis of Small and Medium-sized Airports Based on Improved Bayesian Network Model. In Proceedings of the 2024 IEEE 4th International Conference on Information Technology, Big Data and Artificial Intelligence (ICIBA), Chongqing, China, 6–8 December 2024; Volume 4, pp. 1650–1655. [Google Scholar]
  99. Ma, Z.; Xiao, Y.; Chen, X. Research on Passenger 3D View Focus of Attention at Airport Terminal Based on Massmotion. In Proceedings of the IOP Conference Series: Materials Science and Engineering; IOP Publishing: Bristol, UK, 2020; Volume 780, p. 062047. [Google Scholar]
  100. Moukafih, N.; Zhang, H.; Epiphaniou, G.; Maple, C.; Taylor, S.; Carmichael, L. Semi-automated threat vulnerability & risk assessment (tvra) for medical devices. In Proceedings of the 17th International Conference on PErvasive Technologies Related to Assistive Environments, Crete, Greece, 26–28 June 2024; pp. 687–693. [Google Scholar]
  101. Avci, O.; Ozbulut, O. Threat and vulnerability risk assessment for existing subway stations: A simplified approach. Case Stud. Transp. Policy 2018, 6, 663–673. [Google Scholar] [CrossRef] [Scilit]
  102. Rossebø, J.E.; Cadzow, S.; Sijben, P. e TVRA, a Threat, Vulnerability and Risk Assessment Tool for e Europe. In International Conference on Trust Management; Springer: Berlin/Heidelberg, Germany, 2006; pp. 467–471. [Google Scholar]
  103. Alostaz, Y. TVRA and application to a transit center: A case history study. In Structures Congress 2023; American Society of Civil Engineers: Reston, VA, USA, 2023; pp. 30–38. [Google Scholar]
  104. Madani, A.; Taj, N. IMS SIP Server security model using the TVRA methodology. Signal Data Process. 2015, 1, 17–32. [Google Scholar]
  105. Meer, J.D.; Rennoch, A. The ETSI TVRA security-measurement methodology by means of TTCN-3 Notation. In Proceedings of the TTCN-3 User Conference (T3UC) 2011, Bled, Slovenija, 7–9 June 2011. [Google Scholar]
  106. Institute for Economics & Peace. Measuring The Impact of Terrorism: Global Terrorism Index 2025; Technical Report; Institute for Economics & Peace: Sydney, Australia, 2020; Available online: http://visionofhumanity.org/resources (accessed on 27 April 2026).
Figure 1. Airport Threat.
Figure 1. Airport Threat.
Applsci 16 05406 g001
Figure 2. Literature Review Process.
Figure 2. Literature Review Process.
Applsci 16 05406 g002
Figure 3. Transport Security Framework.
Figure 3. Transport Security Framework.
Applsci 16 05406 g003
Figure 4. Three-step resilience framework [39,40].
Figure 4. Three-step resilience framework [39,40].
Applsci 16 05406 g004
Figure 5. (a,b) Resilience process under different system conditions.
Figure 5. (a,b) Resilience process under different system conditions.
Applsci 16 05406 g005
Figure 6. Location of airport facilities.
Figure 6. Location of airport facilities.
Applsci 16 05406 g006
Figure 7. Mock TVRA Results.
Figure 7. Mock TVRA Results.
Applsci 16 05406 g007
Table 1. Systematic comparison of risk assessment approaches discussed in this review.
Table 1. Systematic comparison of risk assessment approaches discussed in this review.
ApproachRepresentative MethodsMain Functions and StrengthsMain Limitations
Logic-based risk assessment approachesFTA, ETA, FMEA, Bow-tie analysisThese approaches use formal logical representations to decompose hazards, identify causal pathways, and evaluate barrier performance. FTA identifies combinations of basic causal events leading to an undesired top event. ETA maps alternative success–failure sequences after an initiating event. Bow-tie analysis combines upstream causes and downstream consequences, while FMEA identifies component- or process-level failure modes.These models rely on static logic and binary event representations, which limit their ability to capture temporal evolution, multi-state behaviour, and conditional dependencies. ETA requires reliable estimates of barrier performance, while FMEA is sensitive to subjective scoring and struggles to represent interdependencies and emergent behaviours.
Probabilistic risk assessment approachesBN, DBN, PRAThese methods support causal probabilistic reasoning under uncertainty, temporal state-evolution modelling, integrated frequency–consequence analysis, and vulnerability assessment. BN supports diagnostic and predictive inference through conditional dependencies. DBN extends this by modelling temporal evolution across time slices. PRA integrates scenario identification, frequency estimation, and consequence modelling.BN may scale poorly with increasing network complexity, making inference computationally intensive and probability elicitation resource-intensive. DBN adds further temporal data requirements and computational costs. PRA may suffer from incomplete scenarios and simplified representations of human and organisational behaviour.
Operational and behaviour-oriented risk assessment approachesMonte Carlo-based PRA, queueing-network models, discrete-event simulation, ABM, pedestrian-dynamics simulationThese approaches model behavioural, temporal, and spatial dynamics in airport environments. Monte Carlo-based PRA and queueing simulations support the evaluation of equipment failures, stochastic demand, waiting times, queue lengths, staffing, and lane configurations. ABM represents passengers, operators, and attackers as autonomous agents, while pedestrian-dynamics simulation models continuous-space movement and crowd-density effects.These approaches require accurate stochastic inputs, failure distributions, detailed geometric data, movement data, and behavioural assumptions. They also face calibration and validation challenges because empirical data for rare or security-sensitive events are limited, and computational demands increase with scenario complexity.
TVRAParameterised likelihood–vulnerability–impact assessmentTVRA hierarchically decomposes the security research framework into more quantifiable sub-parameters. It calculates risk through likelihood, vulnerability, and impact factors, and supports the prioritisation of identified risk points. It offers clear objectives, supports targeted research into specific threat scenarios or critical assets, reduces the burden of data collection and analysis, and can be adapted to similar scenarios through modified sub-parameter definitions.TVRA requires explicit definitions of critical assets and potential threat scenarios, which may increase time and resource expenditure. It does not fully account for mutual impacts across different threat scenarios, and the quantified sub-parameters are based on comparative analysis rather than precise data. Therefore, it should be integrated with other risk analysis approaches or complementary methods to calibrate or refine the results.
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content.

Share and Cite

MDPI and ACS Style

Li, L.; Li, Y.; Ochieng, W.Y.; Proud, W.G.; Huang, M.; El Hajj, M.; Majumdar, A. A Review of Airport Security and Resilience Analysis: Integration of Risk Modelling Frameworks. Appl. Sci. 2026, 16, 5406. https://doi.org/10.3390/app16115406

AMA Style

Li L, Li Y, Ochieng WY, Proud WG, Huang M, El Hajj M, Majumdar A. A Review of Airport Security and Resilience Analysis: Integration of Risk Modelling Frameworks. Applied Sciences. 2026; 16(11):5406. https://doi.org/10.3390/app16115406

Chicago/Turabian Style

Li, Lintong, Yunhao Li, Washington Yotto Ochieng, William Graham Proud, Mingyang Huang, Mireille El Hajj, and Arnab Majumdar. 2026. "A Review of Airport Security and Resilience Analysis: Integration of Risk Modelling Frameworks" Applied Sciences 16, no. 11: 5406. https://doi.org/10.3390/app16115406

APA Style

Li, L., Li, Y., Ochieng, W. Y., Proud, W. G., Huang, M., El Hajj, M., & Majumdar, A. (2026). A Review of Airport Security and Resilience Analysis: Integration of Risk Modelling Frameworks. Applied Sciences, 16(11), 5406. https://doi.org/10.3390/app16115406

Note that from the first issue of 2016, this journal uses article numbers instead of page numbers. See further details here.

Article Metrics

Back to TopTop