SEO Title
GAO Report Finds FAA Gaps in National Airspace Comms Cybersecurity Monitoring
Subtitle
GAO makes nine recommendations to strengthen FAA cybersecurity
Subject Area
Teaser Text
A GAO report finds the FAA lacks real-time detection for spectrum-based cyberattacks and says ACARS and CPDLC messaging is vulnerable to spoofing.
Content Body

The FAA lacks real-time tools to detect and combat spectrum-based cyberattacks—including spectrum interference, spoofing, and jamming—against aircraft communications in the National Airspace System (NAS), according to a Government Accountability Office report published this week. Without real-time tools, the FAA can investigate attacks only after they are reported, the GAO noted.

Notably, the GAO found vulnerabilities in aircraft communications addressing and reporting system (ACARS) and controller-pilot data link communications (CPDLC) messages, the text-based systems pilots, airlines, and air traffic controllers can use to exchange flight plans, clearances, and other operational information. Because the two systems generally lack encryption and authentication, the GAO said messages can be intercepted, spoofed, or blocked through denial-of-service attacks. “A malicious actor could transmit fraudulent clearance cancellations, possibly leading to flight delays or safety issues,” the report states.

The GAO made nine recommendations to address vulnerabilities, including completing formal risk assessments for seven NAS systems; implementing continuous threat monitoring; and developing a plan to strengthen authentication and data protection of ACARS and CPDLC messages. The DOT concurred with all nine recommendations.

The FAA fully addressed two of eight leading interagency collaboration practices the GAO identified and partially addressed the remaining six; it has not set formal policies for information sharing, reporting, or coordination with non-federal partners outside interagency groups such as the Aviation Cyber Initiative, the GAO found.

After it reviewed eight spectrum-dependent NAS systems, the GAO found that the FAA had not completed separate, detailed risk assessments for seven of them, as required under National Institute of Standards and Technology guidance. The GAO also found that four of the eight systems still referenced an outdated NIST security-control standard that was superseded in 2021.

“Without comprehensive risk and mitigation assessments, complete security documentation, and real-time monitoring capabilities, FAA may not have sufficient information to identify, prioritize, and respond to evolving spectrum-related threats,” the GAO said in the report.

The report was released under a provision of a 2025 law that directed the GAO to review the NAS’ vulnerability to spectrum attacks.

Expert Opinion
False
Ads Enabled
True
Used in Print
False
Writer(s) - Credited
Amy Wilder
Newsletter Headline
U.S. GAO: National Airspace Comms Vulnerable to Spoofing
Newsletter Body

The FAA lacks real-time tools to detect and combat spectrum-based cyberattacks—including spectrum interference, spoofing, and jamming—against aircraft communications in the National Airspace System (NAS), according to a new Government Accountability Office report. Without real-time tools, the FAA can investigate attacks only after they are reported, the GAO notes.

Notably, the GAO found vulnerabilities in aircraft communications addressing and reporting system (ACARS) and controller-pilot data link communications (CPDLC) messages, the text-based systems pilots, airlines, and air traffic controllers can use to exchange flight plans, clearances, and other operational information. Because the two systems generally lack encryption and authentication, the GAO said messages can be intercepted, spoofed, or blocked through denial-of-service attacks. “A malicious actor could transmit fraudulent clearance cancellations, possibly leading to flight delays or safety issues,” the report states.

The GAO made nine recommendations to address vulnerabilities, including completing formal risk assessments for seven NAS systems; implementing continuous threat monitoring; and developing a plan to strengthen authentication and data protection of ACARS and CPDLC messages. The DOT concurred with all nine recommendations.

“Without comprehensive risk and mitigation assessments, complete security documentation, and real-time monitoring capabilities, FAA may not have sufficient information to identify, prioritize, and respond to evolving spectrum-related threats,” the GAO said.

Solutions in Business Aviation
0
AIN Publication Date
World Region
----------------------------