← Back to NASA Technology Projects
Automated VuLnerability Assessment and Risk Mitigation for Future Aviation Systems Safety, ALARM
Completed
TRL 3 (started at 3, targeting 6)
Description
The integration and digital connection of the future National Airspace System (NAS) with new entrants, such as the Unmanned Aircraft Systems (UAS) and Advanced Air Mobility (AAM), provides more pathways for hackers to attack the networked aircrafts and spacecrafts. In order to maintain cyber safety of this integration, security systems and technologies are required to enable on-board monitoring, detection, assessment, and reporting of abnormal events, suspicious behaviors, and potential threats. NASA is currently developing ground and vehicle based In-Time System-Wide Safety Assurance (ISSA) capabilities to monitor, assess and mitigate safety threats. These capabilities will be integrated into an In-Time Aviation Safety Management System (IASMS) to achieve enhanced system-level safety assessment, such as hazard identification, risk management and control, and safety performance evaluation. However, the state-of-the-art cyber technologies face several challenges when adopting into the NAS, such as limited communication bandwidth, limited onboard processing capability, limited memory, and storage capabilities, as well as lack of meaningful data for deep security analysis and modeling. To address this critical need, University Technical Services, Inc. (UTS) proposes to develop an automated vulnerability assessment and risk mitigation (ALARM) system, to provide real-time cybersecurity vulnerability monitoring, assessment, and mitigation for the future aviation systems safety. The key innovation of this work is the development of real-time aviation systems monitoring, machine learning (ML)-based cyber threat detection, proactive vulnerability assessment and risk analysis, as well as advanced aviation and space cyber threat intelligence (CTI) to support comprehensive security analysis and threat mitigation. The proposed technology, will achieve a breakthrough in the computational efficiency for aviation and space systems cybersecurity assessment and risk analysis. Future National Airspace System (NAS) has an increasing need for new entrants, such as Unmanned Aircraft Systems (UAS) and Advanced Air Mobility (AAM), to perform national security and defense missions, emergency management, and critical commercial applications. Cyber safety, security mechanisms are required to enable onboard monitoring, anomaly detection, threat assessment, mitigation, and reporting. NASA is developing ground and vehicle-based, In-Time System-Wide Safety Assurance (ISSA) capabilities to monitor, assess and mitigate threats integrated into an In-Time Aviation Safety Management System (IASMS) to achieve enhanced system-level safety and performance needs. The key to this effort is an automated vulnerability assessment and risk mitigation (ALARM) system, to provide real-time cybersecurity vulnerability monitoring, assessment, and mitigation for future aviation systems' safety. This innovation is applicable to all forms of aviation in airspace and aircraft operations. It can be integrated into the ISSA and IASMS for system-level cybersecurity and safety assessment. Objective 1: Develop aviation systems monitoring capability to support real-time data collection, distribution, and processing. There are multiple systems on the aircraft, such as navigation system, control system, communication system, and autopilot system. These systems are vulnerable to cyberattacks. We will develop capabilities to automatically collect system logs, sensor readings, and traffic data from various systems on the aircraft. Integrated data governance will be provided to improve data quality. Objective 2: Develop advanced analytics models for cyber threat detection, assessment, and mitigation. To achieve both efficiency and effectiveness, we will implement a comprehensive approach which combines heuristic analysis, advanced traffic analysis, and machine learning (ML) based anomaly detection, to accurately detect various cyber threats in near real-time and provide enhanced security analysis (e.g., risk analysis, prediction, and mitigation). Deliverables: a) Kickoff meeting within 30 days of start of contract b) Bimonthly progress reports c) Monthly Technical Review meetings d) Final briefing e) Demonstration and Final Report with SF298.
Benefits
Our technology addresses a critical need in NASA’s strategic goals to advance the state-of-the-art in the autonomous flight operations and onboard cyber and system security. Within NASA, the Unmanned Aircraft Systems (UAS) in the National Airspace System (NAS) (UAS-NAS) Project, the Advanced Air Mobility (AAM) project, and the System-Wide Safety (SWS) project will directly benefit from ALARM. ALARM can directly provide the In-Time System-Wide Safety Assurance (ISSA) capabilities to NASA’s In-Time Aviation Safety Management System (IASMS). Non-NASA applications include satellite communication programs, networks on-the-move, swarm drone/robotic networks, and UAVs. The proposed technology can be directly applied to Urban Air Mobility (UAM) systems. All aircraft need to be protected against potential cyberattacks and malware, as they rely on third party services to operate. ALARM is ideally positioned to support this aviation need.
Details
| Technology area | Air Traffic Management and Range Tracking Systems |
| Program | Small Business Innovation Research/Small Business Tech Transfer (SBIR/STTR) |
| Lead organization | Ames Research Center, Moffett Field, CA |
| Start date | 2024-07-12 |
| End date | 2025-11-13 |
Project contacts
Listed on TechPort itself — the most direct way to ask about this specific project.
How to get involved
This is early/mid-stage (TRL 3) — the most realistic path in is NASA SBIR/STTR, which funds small businesses and research institutions to develop technology aligned with NASA's needs (equity-free, phased funding). Check whether a current SBIR/STTR solicitation topic overlaps with this project's technology area, or contact the project directly (above) to ask.
None of these are guaranteed paths for this specific project — TechPort itself doesn't have an "apply" button. Reaching out to the contact(s) above with a specific question is usually the fastest way to find out what's actually open.