A report from the U.S. Government Accountability Office (GAO) has found that the Federal Aviation Administration (FAA) has not adequately addressed significant cybersecurity risks to the U.S. National Airspace System (NAS). The GAO identified major deficiencies, including a failure to complete risk assessments for critical systems and, most notably, the absence of a real-time capability to detect and monitor for electromagnetic spectrum threats like spoofing and jamming. These gaps expose vital air-to-ground communication systems to potential manipulation, posing risks to aviation safety and operational efficiency. The GAO has issued nine recommendations for the FAA to address these shortcomings.
The GAO report highlights systemic weaknesses rather than a single CVE. The core vulnerability is the FAA's lack of a proactive, real-time security monitoring posture for the electromagnetic spectrum used by aircraft.
A successful cyberattack exploiting these weaknesses could have serious consequences:
The report's main point is the lack of observability. However, to build such a capability, the FAA would need to hunt for:
The GAO's primary recommendation is for the FAA to develop detection methods. This would involve:
D3-NTA - Network Traffic Analysis.The GAO issued nine recommendations to the FAA, which serve as a remediation roadmap:
D3-MENCR - Message Encryption.The core of the GAO's recommendation is for the FAA to implement a real-time audit and monitoring capability for the NAS.
Long-term remediation requires moving to communication protocols that encrypt and authenticate messages to prevent spoofing.
Implementing measures to verify that communication is from a trusted source, which is currently lacking in ACARS/CPDLC.
The GAO report's central finding is the FAA's lack of real-time monitoring, a gap that Network Traffic Analysis is designed to fill. For the aviation context, this isn't traditional IP network analysis but rather Radio Frequency (RF) spectrum analysis. The FAA needs to deploy a nationwide network of sensors capable of monitoring the frequency bands used by ACARS, CPDLC, and other NAS systems. These sensors would baseline normal signal characteristics and locations. A D3FEND-based NTA system would then alert on anomalies indicative of an attack: a jamming signal overpowering legitimate communications, an ACARS message being broadcast from a location with no aircraft (a spoofing attempt), or signals with incorrect modulation. This provides the real-time detection capability the GAO found was missing, allowing for immediate investigation and mitigation.
To fundamentally fix the spoofing vulnerability in legacy systems like ACARS and CPDLC, the FAA and aviation industry must adopt Message Encryption and authentication. This is a long-term strategic mitigation. Future versions of these protocols must incorporate cryptographic signatures to ensure message authenticity (i.e., proving a message came from the claimed aircraft or ground station) and integrity (i.e., proving the message was not altered in transit). This would likely involve a Public Key Infrastructure (PKI) for aviation. A spoofed message, such as a fake clearance cancellation, would be immediately rejected by the recipient's system because it would lack a valid digital signature. This D3FEND technique moves from detection to prevention, making spoofing attacks against next-generation datalink systems computationally infeasible.
The Government Accountability Office (GAO) publishes its report on FAA cybersecurity weaknesses.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.