GAO Finds FAA Lacks Real-Time Aviation Cyber Threat Monitoring

GAO: FAA Lacks Real-Time Monitoring for Aviation Cyber Threats

HIGH
September 24, 2026
4m read
Industrial Control SystemsPolicy and ComplianceCyberattack

Related Entities

Organizations

Government Accountability Office (GAO)Federal Aviation Administration (FAA)

Products & Tech

National Airspace System (NAS)Aircraft Communications Addressing and Reporting System (ACARS)Controller-Pilot Data Link Communications (CPDLC)

Full Report

Executive Summary

A report from the U.S. Government Accountability Office (GAO) has found that the Federal Aviation Administration (FAA) has not adequately addressed significant cybersecurity risks to the U.S. National Airspace System (NAS). The GAO identified major deficiencies, including a failure to complete risk assessments for critical systems and, most notably, the absence of a real-time capability to detect and monitor for electromagnetic spectrum threats like spoofing and jamming. These gaps expose vital air-to-ground communication systems to potential manipulation, posing risks to aviation safety and operational efficiency. The GAO has issued nine recommendations for the FAA to address these shortcomings.


Vulnerability Details

The GAO report highlights systemic weaknesses rather than a single CVE. The core vulnerability is the FAA's lack of a proactive, real-time security monitoring posture for the electromagnetic spectrum used by aircraft.

Key Deficiencies:

  • Lack of Real-Time Monitoring: The FAA does not have a defined capability to detect spectrum-based attacks as they happen. It relies on post-incident investigations after an event has already been reported by pilots or air traffic control.
  • Incomplete Risk Assessments: The agency has not completed formal risk and mitigation assessments for known threats against seven critical NAS systems.
  • Vulnerable Communication Systems: Legacy text-based communication systems like the Aircraft Communications Addressing and Reporting System (ACARS) and Controller-Pilot Data Link Communications (CPDLC) are particularly at risk. These systems often lack robust authentication and encryption, making them vulnerable to:
    • Spoofing: An attacker could impersonate air traffic control or an aircraft and transmit false messages, such as fake clearance cancellations or altitude changes.
    • Jamming: An attacker could disrupt communications, degrading pilots' situational awareness and forcing a reversion to voice communications, which can increase controller workload and cause delays.

Affected Systems

  • National Airspace System (NAS): The entire complex network of systems, procedures, and equipment used to manage air traffic in the U.S.
  • Aircraft Communications Addressing and Reporting System (ACARS): A digital datalink system for transmitting short messages between aircraft and ground stations.
  • Controller-Pilot Data Link Communications (CPDLC): A text-based communication system that supplements voice communications for air traffic control clearance.
  • Seven other unnamed NAS systems for which risk assessments are incomplete.

Impact Assessment

A successful cyberattack exploiting these weaknesses could have serious consequences:

  • Safety Risks: Spoofed messages could lead to pilot confusion, loss of separation between aircraft, or incorrect flight maneuvers, particularly in busy airspace.
  • Operational Delays: Jamming or spoofing attacks could force widespread reversion to already congested voice channels, leading to significant flight delays and air traffic congestion.
  • Erosion of Trust: A successful attack would undermine trust in the next-generation digital communication systems that are essential for modernizing air traffic management.

Cyber Observables — Hunting Hints

The report's main point is the lack of observability. However, to build such a capability, the FAA would need to hunt for:

Type
network_traffic_pattern
Value
Anomalous RF signal behavior
Description
Using spectrum analyzers to detect signals that are unusually strong, have incorrect modulation, or originate from unexpected locations.
Type
other
Value
Mismatched ACARS/CPDLC message data
Description
Correlating message data with flight plan data and ADS-B position data to identify messages that are logically inconsistent.
Type
log_source
Value
Aircraft and Ground Station Communication Logs
Description
Analyzing logs for repeated, malformed, or unauthenticated messages that could indicate a spoofing attempt.

Detection Methods

The GAO's primary recommendation is for the FAA to develop detection methods. This would involve:

  1. Spectrum Monitoring: Deploying a network of radio frequency (RF) sensors in key locations to continuously monitor the aviation spectrum for signs of jamming or illegitimate transmissions. This is a specialized form of D3FEND's D3-NTA - Network Traffic Analysis.
  2. Protocol Analysis: Implementing systems that can analyze the content and metadata of ACARS and CPDLC messages in real time to detect anomalies and potential spoofing.
  3. Data Correlation: Fusing data from spectrum monitoring, communication logs, and flight tracking systems (like ADS-B) to identify discrepancies that could indicate a cyberattack.

Remediation Steps

The GAO issued nine recommendations to the FAA, which serve as a remediation roadmap:

  1. Implement Continuous Monitoring: Develop and deploy a real-time threat monitoring capability for the aviation spectrum.
  2. Complete Risk Assessments: Finalize the required risk and mitigation assessments for all critical NAS systems.
  3. Update Security Documentation: Update security plans and protocols to reflect the current threat landscape.
  4. Modernize Communication Protocols: In the long term, the FAA and the aviation industry must move towards next-generation communication systems that incorporate strong, end-to-end encryption and message authentication (e.g., using Public Key Infrastructure). This aligns with D3FEND's D3-MENCR - Message Encryption.

Timeline of Events

1
September 21, 2026
The Government Accountability Office (GAO) publishes its report on FAA cybersecurity weaknesses.
2
September 24, 2026
This article was published

MITRE ATT&CK Mitigations

Audit

M1047enterprise

The core of the GAO's recommendation is for the FAA to implement a real-time audit and monitoring capability for the NAS.

Long-term remediation requires moving to communication protocols that encrypt and authenticate messages to prevent spoofing.

Implementing measures to verify that communication is from a trusted source, which is currently lacking in ACARS/CPDLC.

D3FEND Defensive Countermeasures

The GAO report's central finding is the FAA's lack of real-time monitoring, a gap that Network Traffic Analysis is designed to fill. For the aviation context, this isn't traditional IP network analysis but rather Radio Frequency (RF) spectrum analysis. The FAA needs to deploy a nationwide network of sensors capable of monitoring the frequency bands used by ACARS, CPDLC, and other NAS systems. These sensors would baseline normal signal characteristics and locations. A D3FEND-based NTA system would then alert on anomalies indicative of an attack: a jamming signal overpowering legitimate communications, an ACARS message being broadcast from a location with no aircraft (a spoofing attempt), or signals with incorrect modulation. This provides the real-time detection capability the GAO found was missing, allowing for immediate investigation and mitigation.

To fundamentally fix the spoofing vulnerability in legacy systems like ACARS and CPDLC, the FAA and aviation industry must adopt Message Encryption and authentication. This is a long-term strategic mitigation. Future versions of these protocols must incorporate cryptographic signatures to ensure message authenticity (i.e., proving a message came from the claimed aircraft or ground station) and integrity (i.e., proving the message was not altered in transit). This would likely involve a Public Key Infrastructure (PKI) for aviation. A spoofed message, such as a fake clearance cancellation, would be immediately rejected by the recipient's system because it would lack a valid digital signature. This D3FEND technique moves from detection to prevention, making spoofing attacks against next-generation datalink systems computationally infeasible.

Timeline of Events

1
September 21, 2026

The Government Accountability Office (GAO) publishes its report on FAA cybersecurity weaknesses.

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

FAAGAOAviation SecuritySpoofingJammingACARSCPDLCNAS

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

⚡ Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.