← Back to NASA Technology Projects

Advanced Threat Analysis and Remediation on Aggregated Air Vehicle ACARS

Completed

Description

The presented solution provides advanced threat analysis using Artificial Intelligence (AI) on aggregated ACARS (Aircraft Communications Addressing and Reporting System) messages. The analysis, performed in near real time (in-time), will identify anomalies across the data set based on deviations from baselined ‘normal’ operations. The system will provide cross-reference checking across the data set to identify emerging and active threats against single end points (e.g. air vehicles), and system-wide attacks on the National Air Space (NAS). The AI would offer mitigations for the threats/attacks.

Benefits

Identification of system wide threats and recommendation of mitigating actions to support the System Wide Safety initiative. Several threats can be identified via AI analysis of ACARS messages. • Ground-Based Spoofing: An attacker with an SDR (software-defined radio) fakes ACARS messages to report false BIT faults, tricking ground crews or triggering unsafe Avionics & Sensors responses. • Avionics & Sensors Malware: A compromised onboard system (e.g., via a maintenance laptop) sends rogue BIT data via ACARS to mislead or disrupt. • Injection Attack: A malicious ACARS message (e.g., REBOOT FMS) exploits vulnerability in the Avionics & Sensors-ACARS interface. • Eavesdropping Exploitation: An attacker uses intercepted BIT data (e.g., engine states) to plan physical or cyber follow-ups. In addition to the specific threats against air system end points detailed above, the AI could correlate data to find attacks against the NAS as a whole. For example: 1. Coordinated Spoofing Across Aircraft 2. ATC Datalink Disruption (CPDLC Attacks) 3. Ground Station Compromise 4. System-Wide Denial of Service (DoS) 5. Data-Driven Airspace Exploitation This innovation offers substantial economic value by strengthening aviation cybersecurity. It could save airlines $5-7 billion annually by reducing cyber-incident costs, currently estimated at $1-2 million per event - Commercial Aviation (Airlines and Operators) Application: Airlines (e.g., Delta, United) or private jet operators (e.g., NetJets) could deploy the system to monitor their fleets’ ACARS traffic for cyber threats independently of FAA mandates, enhancing operational security. - Unmanned Aircraft Systems (UAS) Operators Application: Drone companies (e.g., Amazon Air, UPS Flight Forward) could adapt the system for their control link protocols (similar to ACARS) to secure last-mile delivery or surveillance drones. - Maritime Industry Application: Ship operators could use a variant to monitor AIS (Automatic Identification System) data—akin to ADS-B—for cyber threats like spoofed vessel locations. - Logistics and Supply Chain Application: Trucking or rail companies could apply the system to secure GPS/telematics data, detecting cyber attacks on fleet tracking. - Critical Infrastructure (Energy, Telecom) Application: Power grids or telecom networks could use it to monitor SCADA (Supervisory Control and Data Acquisition) messages—similar to ACARS—for cyber intrusions. - Cybersecurity Research and Consulting Application: Sell the system as a tool to firms (e.g., CrowdStrike, Palo Alto Networks) for analyzing proprietary data streams in non-aviation contexts

Details

Technology areaFlight Computing and Avionics
ProgramSmall Business Innovation Research/Small Business Tech Transfer (SBIR/STTR)
Lead organizationGlenn Research Center, Cleveland, OH
Start date2025-09-29
End date2026-03-27

Project contacts

Listed on TechPort itself — the most direct way to ask about this specific project.

How to get involved

This is a mature technology (TRL 7+) — the realistic path in is usually NASA's Technology Transfer Program: licensing an existing NASA patent, or a Space Act Agreement to use NASA facilities/expertise directly. NASA also runs a startup licensing program with no upfront fee for companies formed to commercialize a specific NASA technology.

None of these are guaranteed paths for this specific project — TechPort itself doesn't have an "apply" button. Reaching out to the contact(s) above with a specific question is usually the fastest way to find out what's actually open.