Skip to main content

Airline Application Security in the Digital Economy: Tackling Security Challenges for Distributed Applications in Lufthansa Systems

  • Chapter
  • First Online:
Book cover Digitalization Cases

Abstract

  1. (a)

    Situation faced: In the era of pervasive digitalization, the airline IT software industry is facing a number of challenges from the combination of new distribution channels, social media, Big data, Cloud Computing, etc. One of the major challenges in creating smart and scalable software applications is how to tackle security challenges when components are distributed and operated in hybrid and multiple clouds, whose providers may be independent and heterogeneous. The difficulties reside not only in identifying and expressing the desired level of security in the application, but also in how the security guarantees are influenced by the cloud services used.

  2. (b)

    Action taken: We exemplify the case with a flight scheduling application prototype developed by Lufthansa Systems and explain how novel approaches are used to address security issues during the development of such a prototype by following the MUSA approach. MUSA stands for Multi-cloud Secure Applications and refers to an EU-funded research project that is developing an integrated solution for the development and operation of secure multi-cloud applications accounting for those security aspects from the beginning. We introduce the MUSA Security DevOps framework and lessons learned from using it.

  3. (c)

    Results achieved: Lufthansa Systems tested MUSA tools in an exercise to create, deploy and control a new secure application prototype. We describe how these tools were used in the context of the case study presented in this paper. We also analyze the impact that they had in the development, deployment, and operation of the multi-cloud prototype. This analysis is done by means of a user-centered evaluation using questionnaires and informal interviews.

  4. (d)

    Lessons learned: The most important lesson is the importance of a sound risk analysis from which the security decisions are taken. MUSA framework supports the automation of the risk analysis in a per component basis, helping to systematize the creation of the application risk profile. Another important aspect is how implementing a SecDevOps approach in a multi-cloud scenario proves that it is highly valuable to include security topics together with the regular DevOps methodology. Finally, we must underline the need for cloud standards which enable homogeneous cloud service descriptions that ease the comparison of the services and the offered security controls.

This is a preview of subscription content, log in via an institution to check access.

Access this chapter

Chapter
USD 29.95
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
eBook
USD 39.99
Price excludes VAT (USA)
  • Available as EPUB and PDF
  • Read on any device
  • Instant download
  • Own it forever
Softcover Book
USD 54.99
Price excludes VAT (USA)
  • Compact, lightweight edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info
Hardcover Book
USD 84.99
Price excludes VAT (USA)
  • Durable hardcover edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Purchases are for personal use only

Institutional subscriptions

Notes

  1. 1.

    The MUSA solution is the main result of the project MUSA—Multi-cloud Secure Applications project of the European Union’s Horizon 2020 research and innovation programme under grant agreement No 644429.

  2. 2.

    https://www.mongodb.com

  3. 3.

    https://kafka.apache.org/

  4. 4.

    https://zookeeper.apache.org/

  5. 5.

    https://www.chef.io/chef/

  6. 6.

    https://cloudsecurityalliance.org/media/news/consensus-assessments-initiative-questionnaire-caiq-v-3-review/

  7. 7.

    https://kubernetes.io/

  8. 8.

    https://mesosphere.github.io/marathon/

  9. 9.

    https://www.elastic.co/products

References

Download references

Acknowledgements

This work is supported by the European Commission through the MUlti-cloud Secure Applications (MUSA) project under Project ID: 644429.

Author information

Authors and Affiliations

Authors

Corresponding author

Correspondence to Oscar Ripolles .

Editor information

Editors and Affiliations

Rights and permissions

Reprints and permissions

Copyright information

© 2019 Springer International Publishing AG, part of Springer Nature

About this chapter

Check for updates. Verify currency and authenticity via CrossMark

Cite this chapter

Somoskői, B. et al. (2019). Airline Application Security in the Digital Economy: Tackling Security Challenges for Distributed Applications in Lufthansa Systems. In: Urbach, N., Röglinger, M. (eds) Digitalization Cases. Management for Professionals. Springer, Cham. https://doi.org/10.1007/978-3-319-95273-4_3

Download citation

Publish with us

Policies and ethics