News:

Precision Simulator update 10.194 (12 September 2026) is now available.
Navburo update 13 (23 November 2022) is now available.
NG FMC and More is released.

Main Menu

GPS Spoofing

Started by Tom Gorzenski, Sat, 28 Oct 2023 07:52

Jeroen Hoppenbrouwers

No, not retrofit of an IRS -- all airplanes have one. But many modern airplanes have an integrated nav unit where the IRS has been made subordinate to GPS. IRS takes over seamlessly when GPS fails, but when GPS is spoofed without detecting it, you cannot tell the unit to abandon GPS.

ADS-B IN can be spoofed easily, just as TCAS: just overpower the signals. None of the traditional protocols (ACARS, any VHF or HF comms, ADS-B, TCAS, transponder, ILS, VOR, GPS, DME, RA, ...) is even remotely resilient against jamming or spoofing, there is zero IT-style security, only laws attempting to keep other transmitters out of the way. Even these laws are now challenged by competing laws (the whole RA and GPS/L-band fiasco around 5G, LightSquared/Ligado).

None of this was ever designed with intentional malicious interference in mind. Safety, yes: there are procedures for everything when it fails. But safety is not the same as security (and actually both concepts bite eachother in many cases).

To be fair, those older technologies were cutting edge when introduced and the equipment at that time truly had no hope of ever incorporating encryption. It is way too expensive and too complex to put military-grade security into commercial aviation equipment now. So newer systems (like ACARS over IP and the future IPS replacement for ATN) will have it, like most satellite systems since about 2015, but I don't see a complete move-over.

Besides, I won't fly my airplane over a contested area where GPS jamming is paramount, as there will be nice SAM launchers there as well. Avionics threats are a weapon nowadays, they deny commercial aviation access even without threatening to bring down airplanes.

Tom Gorzenski

#61
As some have been saying for 20 years, it's time to make LORAN great again. This time in the form of eLORAN.
Meanwhile in China:
https://www.gpsworld.com/china-completes-national-eloran-network/

Tom Gorzenski

#62
Oh, and by the way:
https://www.faa.gov/about/office_org/headquarters_offices/avs/offices/afx/afs/afs400/afs410/GNSS/GPS_GNSS_Interference_Resource_Guide.pdf

In the context of training and PSX:
"5.3 Flight Training Pilots should train with written procedures/checklists to be prepared for possible jamming and/or spoofing. Simulator training should incorporate the following:
- Unexpected TAWS alerts and goarounds at higher altitudes other than the typical go-around on short final,
- TAWS alerts in the approach phase and spurious warnings at various other phases of flight,
- Scenarios that simulate a corrupted FMS position causing the aircraft to turn off the previously established route,
- Simulated position shift on the navigation display including during an approach,
- Scenarios that simulate the aircraft clock changing from the correct UTC,
- Practice of briefings for entering possible areas of jamming and/or spoofing,
- Simulation of multiple failures of aircraft systems that have a GNSS component that is spoofed,
- Simulation of spoofing on the ground during taxi and properly addressing the anomalies,
- Practice of alternative navigation to using ground-based NAVAIDs and a ground-based NAVAID approach (i.e. Localizer, ILS, VOR, NDB, etc.)"

andrej

Little off topic, but I think that I was a victim of GPS spoofing. Or maybe I am taking too much credit?

Andrej

Jeroen Hoppenbrouwers

Plausible at least.

Hardy Heinlin

I'm experimenting with spoofing the GPS model in PSX. As expected, it opens a cup of worms. It's not as trivial as just overwriting a pair of lat/lon numbers. There are a lot of interdependancies within the FMC.

As we know, – and this is modelled in PSX – the FMC takes a position bias into account which can be purged by the crew.

For a test, I do this:

1. I spoof the PSX GPS.
2. The GPS position display on the CDU shows the spoofed position.
3. The FMC uses that spoofed GPS position as an aircraft position reference (route data, ND etc. behave accordingly).
4. I click the GPS INHIBIT on the CDU (or fail both GPS units).
5. The FMC goes to "IRS NAV ONLY" mode.
6. The position bias generated by the spoof remains.
7. I click the PURGE key on the CDU.
8. The spoofed bias is removed, the FMC position goes to the mixed IRS position (which is useable).

Is this realistic? That means, the spoofing may be active for just a few seconds and then disappear, and that's long enough to generate that bias in the FMC. In other words, to generate a permanent problem, the spoofing doesn't need to be permanent. Just a short error injection is required. And the FMC will keep this error – until the crew pushes the PURGE key.

Does that make sense?


|-|ardy

Hardy Heinlin

How do you disable the spoofed GPS time in the FMC?

As we know:
If GPS is available, the FMC uses GPS time, else:
If the left clock is operative, the FMC uses the left clock, else:
the FMC uses the right clock.

In order to make the GPS unavailable, the crew needs to pull the GPS circuit breakers. Then the FMC will use the pilot's clock.

Is that procedure correct? Or will the GPS INHIBIT key on the CDU also inhibit the GPS time?

I always refer to the 744, of course :-)

Hardy Heinlin

#67
Why is it so hard to recognize spoofing in flight even though the indicated position will be frozen and the GPS groundspeed indication will read zero?


Edit:

Quote from PDF page 26 of:
https://www.faa.gov/about/office_org/headquarters_offices/avs/offices/afx/afs/afs400/afs410/GNSS/GPS_GNSS_Interference_Resource_Guide.pdf

QuotePilots may not be immediately aware of being spoofed as the aircraft subtly drifts or turns off course.

So the FMC position will not jump but slowly drift to that spoofed position. I guess it's the FMC dampening algorithm that makes the drift slow. The signal itself is hard-coded to the spoofed-to position. But what GPS groundspeed will the FMC calculate during the drift? I assume the groundspeed indication is also dampened and, therefore, will indicate the previous groundspeed value for a long time.

Jeroen Hoppenbrouwers

Obviously I don't know any of these answers as I don't have access to the 744 FMC logic.

Here's a real life example of what I saw happening to one of "my" airplanes over the Black Sea:

GPS UTC {Thu Mar 05 01:17:05 UTC 2026}
GPS UTC {Thu Mar 05 01:27:05 UTC 2026}
GPS UTC {Thu Mar 05 01:37:05 UTC 2026}
GPS UTC {Thu Mar 05 01:47:05 UTC 2026}
GPS UTC {Thu Mar 05 01:57:05 UTC 2026}
GPS UTC {Thu Mar 05 02:07:05 UTC 2026}
GPS UTC {Thu Mar 05 02:17:05 UTC 2026}
GPS UTC {Thu Mar 05 02:27:05 UTC 2026}
GPS UTC {Wed Mar 04 04:46:33 UTC 2026}  <--
GPS UTC {Fri Mar 10 04:02:58 UTC 2028}  <--
GPS UTC {Fri Mar 10 04:07:59 UTC 2028}  <--
GPS UTC {Thu Mar 05 04:27:06 UTC 2026}
GPS UTC {Thu Mar 05 04:37:05 UTC 2026}
GPS UTC {Thu Mar 05 04:47:06 UTC 2026}
GPS UTC {Thu Mar 05 04:57:06 UTC 2026}
GPS UTC {Thu Mar 05 05:07:06 UTC 2026}
GPS UTC {Thu Mar 05 05:17:06 UTC 2026}
GPS UTC {Thu Mar 05 05:27:06 UTC 2026}
GPS UTC {Thu Mar 05 05:37:06 UTC 2026}
GPS UTC {Thu Mar 05 05:47:06 UTC 2026}

The GPS poller runs every 10 minutes as determined by "OS.now+10" so independent of the GPS data. The position at this time (over the Black Sea) moved to Lima city center (!). The missing data values were completely disregarded as the GPS itself reported problems. We miss two hours of reliable time and position.

One of the many side effects of a clock that is off-time, is that many CPDLC messages are being rejected. And once rejected, the whole link and often even the tail become disabled. Much of these troubles are because the software design never took spoofing into account, and is not programmed to recover. A GPS "wot?!" leads to the assumption that the GPS is broken and needs to be ignored until replaced. This mistaken assumption is being addressed, which usually takes several years as core logic needs to be adjusted and therefore recertified from scratch.

Avionics core software is not able to follow security patches as in IT. Design flaws are now being exposed that the development process did not anticipate and the industry cannot speed up. Special GPS monitoring software is now added to the iPad EFB which has none of the certification brakes (which ennerves some people to no end), which at least gives pilots some warning. But the distinction between built-in software that flies the airplane and add-on software that runs on the iPad is hard. Two completely different beasts.


Hoppie

Hardy Heinlin

Here's my GUI plan. I've read that pilots should expect jamming before entering and after leaving a spoofing zone. So I suggest an optional "jamming ring" around the spoofing core zone:



Jeroen Hoppenbrouwers

I am not sure whether jamming and spoofing should go together. Jamming usually means: blasting enough noise in the L-band spectrum to simply overpower the very weak GPS signals. Spoofing on the other hand means to blast very specific signals at very specific frequencies, but more powerful than the GPS signals.

I would expect that a spoof works at a greater distance than a jam; I can imagine that if you want to spoof at 100 nm, you accidentally jam at 50 nm or closer, unless you can direct the beam very precisely at one single target.

If you want to be extremely sophisticated, you can introduce a very specific spoof aimed at just this airplane that moves its apparent position to, say, 10 nm left of track. This shift cannot be calculated by the spoofer as easily as a time shift, but it has happened that a drone was steered pretty nicely to where it did not want to go this way. I think it goes too far for PSX but as a demonstruction it would be interesting.


Hoppie

Hardy Heinlin

#71
My concept is flexible: You can set jam-only or spoof-only or both combined.

For jam-only, set the spoof radius to zero and make the jam zone big. Or deselect the spoofing.

For spoof-only, deselect the jamming.

Time spoofing is another option, independent of position spoofing.


As for the jam/spoof combination: I want to simulate this training scenario here:



Source: Page 34 in ...
https://www.faa.gov/about/office_org/headquarters_offices/avs/offices/afx/afs/afs400/afs410/GNSS/GPS_GNSS_Interference_Resource_Guide.pdf

Are you sure you can spoof a permanent 10 nm offset to a specific aircraft? As far as I understand the trick, the onboard GPS guidance will not jump to the spoof-to position but the onboard GPS guidance itself will slowly drift to it by a rate of some miles per second. This is hard to notice as the offset is increasing slowly. It's the dampening algorithm in the onboard system. There is no jump when you click INHIBIT on the CDU, and there is no jump when you click PURGE. The FMC moves from one reference to the other always slowly. I don't think the spoofer can generate a slow move; it can only set one single fake signal for all aircraft in the vicinity. And the GPS receivers decode that fake signal. The fake signal looks like a sum of signals coming from 3 or 4 satellites in certain space positions, and the avionics "think" these satellites are real.

I think the jamming overpowers the normal GPS, and the spoofing overpowers the jamming.

The jamming provides the canvas, so to speak, and the spoofing paints the ghosts on that canvas.

If you spoof without jamming, the spoofing may not clearly overpower the normal GPS fragments. It might be like receiving two radio stations simultaneously, like hearing Bach and Abba at the same time. The jamming covers the Bach, so that in the remaining noise only Abba can be identified.

Jeroen Hoppenbrouwers

You may be right about the canvas; I am not an R/F specialist by any means.

To "guide" an aircraft would be very, very difficult, but it has happened with probably less fancy drones that may just believe their GPS directly. And yes you cannot pick out one aircraft and leave all others alone. Works ok for one drone over the desert though.


Hoppie

Hardy Heinlin

Or maybe the spoofers use a parabolic antenna to get more directional control?

Jeroen Hoppenbrouwers

That probably would only work if you fly above the target and use a system comparable to a missile aiming tracker. It then almost becomes a remote takeover -- of course very complicated to do. However I bet there are systems available today that can do it. Just not practical with a swarm.

Hardy Heinlin

In cases where they transmit a fixed spoofed-to position, for example a fixed airport position, I think the spoofer just transmits the same signal that a GPS receiver at that airport is receiving. So the spoofed aircraft's GPS receiver will decode the same signal mix that the GPS receiver at that airport is decoding. It's just a complete radio signal copy. No mathematical hacking required.

Jeroen Hoppenbrouwers

Yes, fixed position is absolutely a lot easier to do.

There are today also spoofing methods that change the tables which the GPS receiver uses to know where the satellites are. This is much more hideous as it will typically be stored in the receiver's medium-term memory. Even if the receiver leaves the spoofed area, those tables flow in at a few bits per second, so it takes a long time for them to be downloaded and verified. During that time, you cannot trust the receiver at all.

Will

SAS cockpit video: A350 crew encountering GPS spoofing, and talking about how they deal with it (in real time):

https://youtu.be/4dG_Whxzdkk?t=857

At circa 18:00 they talk about turning off the terrain warnings, and right after that, they ask ATC for a time check. The relief captain talks about watching the GPS time running in reverse in one instance.
Will /Chicago /USA

Jamie

Quote from: Hardy Heinlin on Wed, 25 Mar 2026 16:33In cases where they transmit a fixed spoofed-to position, for example a fixed airport position, I think the spoofer just transmits the same signal that a GPS receiver at that airport is receiving. So the spoofed aircraft's GPS receiver will decode the same signal mix that the GPS receiver at that airport is decoding. It's just a complete radio signal copy. No mathematical hacking required.
Personally I experience the jamming on every flight to the east from Europe between Romania and Turkmenistan. GPS fails, ND position remains, but GPS pos on moving map (EFB) is gone. ADF B L and R faults, GPS L and R faults, randomly appear and annoys a lot. We do some new fancy Boeing checklists, GPS Data unreliable, and switch NAV Inhibit to off (777/787). The clock also jumps around a few hours forward most of the times. Annoying, because this influences the passenger infotainment as well (ETA/ Time at dest etc).

Spoofing only occured to me around Israel, Cyprus and around Egypt. Again no map shift, well it does exist, however I haven't experienced any, not on the Airbus nor the Boeing, but the GPS position on the EFB map jumps around. Sometimes to Beirut, sometimes Cairo. However maps shifts on the ND do occur, I haven't experience them yet in the last say 5 years. And I get jammed/spoofed on every flight.

Jeroen Hoppenbrouwers

Argh.
I suppose you mean ADS-B? That would make sense as it relies indirectly on the GPS position transmissions of other planes that probably also get spoofed. Alternatively it's the Mode-C/S transponder -- that includes TCAS, which is nasty.

Clearly the GPS-only iPad is easier to jam than a hard core airplane GPS. Hey, great that it is no longer needed to feed airplane GPS (from 429 via WiFi) into the EFB, let's use the Apple GPS, why not? It works fine!


Hoppie