GAO Flags FAA Jamming, Spoofing Gaps

Report says FAA lacks continuous monitoring for spectrum threats affecting aviation communications.

GAO Flags FAA Jamming, Spoofing Gaps
[Credit: Thomas Roell | Shutterstock]
Gemini Sparkle

Key Takeaways:

  • A new GAO report found the FAA lacks adequate real-time cybersecurity protections against aviation threats like spoofing and jamming, with incomplete risk assessments for seven out of eight critical spectrum-dependent systems.
  • The FAA's inability to detect spectrum-related threats in real time means it can only investigate incidents after they are reported, and vulnerabilities exist in text-based aircraft communications that could allow fraudulent messages.
  • The report followed a New Mexico air ambulance crash where military GPS jamming was active, highlighting real-world impacts.
  • The GAO issued nine recommendations for strengthening aviation cybersecurity, including continuous monitoring and improved authentication, all of which the FAA has agreed to implement.
See a mistake? Contact us.

The FAA needs stronger protections against aviation cybersecurity threats including spoofing and jamming, according to a new GAO report released Monday. The Government Accountability Office found incomplete risk assessments for several spectrum-dependent systems and said the FAA lacks a defined real-time capability to detect all spectrum-related threats.

Real-Time Monitoring Gap

“While FAA has identified spectrum-related threats, it hasn’t sufficiently addressed them,” the GAO said in the report.

The agency noted that technology exists to monitor such threats in real time, but the FAA does not currently have comparable capabilities.

“Consequently, FAA can only investigate incidents after they’ve been reported.”

The GAO reviewed eight spectrum-dependent systems and found the FAA had not completed formal risk assessments for seven of them. Investigators also identified vulnerabilities involving authentication and encryption in text-based aircraft communications. According to the report, those weaknesses could allow fraudulent messages, including clearance cancellations, to be transmitted.

New Mexico Accident

The report follows a May 14 accident in New Mexico in which a Beech C90 air ambulance crashed near Lincoln, killing both pilots and two flight nurses. An NTSB report said U.S. military GPS jamming was underway in the area during the flight. The crew reported losing GPS capability and requested headings from ATC, while three other aircraft also reported GPS losses. An Albuquerque Center controller asked that the military stop the jamming before the aircraft was cleared for a visual approach. The NTSB investigation remains underway and has not determined a probable cause.

Nine Recommendations

The GAO issued nine recommendations covering spectrum cybersecurity risks and aviation communications security. The recommendations include continuously monitoring interference, spoofing and jamming and strengthening authentication and data protection for ACARS and controller-pilot data link communications. The Department of Transportation, responding on behalf of the FAA, agreed with all nine recommendations.

Matt Ryan

Matt is AVweb's lead editor. His eyes have been turned to the sky for as long as he can remember. Now a fixed-wing pilot, instructor and aviation writer, Matt also leads and teaches a high school aviation program in the Dallas area. Beyond his lifelong obsession with aviation, Matt loves to travel and has lived in Greece, Czechia and Germany for studies and for work.
Sign-up for newsletters & special offers!

Get the latest stories & special offers delivered directly to your inbox

SUBSCRIBE

Please support AVweb.

It looks like you’re using an ad blocker. Ads keep AVweb free and fund our reporting.
Please whitelist AVweb or continue with ads enabled.