ADS-B SECURITY

Ghost aircraft in ADS-B

A ghost aircraft is a track on a map with no real aircraft behind it. Here is how they get produced, why the protocol allows it, how detection actually works, and how honest you should be with yourself about what an odd track proves.

Definition

What a ghost aircraft actually is

A ghost aircraft is an ADS-B track that a receiver decodes and displays, position, altitude, callsign and all, that does not correspond to a real airframe currently occupying that airspace. There are two distinct ways this happens. The first is a fabricated track: a transmitter, whether a software defined radio or purpose-built hardware, broadcasts a complete, well-formed ADS-B message for an aircraft that was never there at all, invented position and identity included. The second is a manipulated track: a real aircraft's broadcast is captured, altered and replayed, or a real ICAO address is reused with a fabricated position, so the identity is genuine but the position or kinematics are not.

Both cases are distinct from ordinary reception noise, a single garbled message that a decoder discards, and from a legitimate aircraft doing something unusual, such as a test flight or an unfamiliar approach pattern. A ghost aircraft, by definition, is a message that decodes cleanly and looks legitimate at the protocol level, which is exactly what makes it hard to catch from the raw data alone.

Why it is possible

ADS-B has no authentication

ADS-B, as specified and deployed today (1090ES and UAT), was designed in an era and for a purpose where authenticating the sender was not a design goal. It transmits position, velocity, identity and integrity information in the clear, with no encryption and no cryptographic signature tying a message to the aircraft that supposedly sent it. This is a well-documented and openly discussed property of the standard, not a secret weakness. Any radio transmitter capable of producing a correctly formatted message on 1090 MHz can generate ADS-B traffic that a receiver has no protocol-level way to distinguish from a genuine transponder. This is why the aviation security literature treats ADS-B spoofing as a known and studied problem rather than a hypothetical one, and why detection has to be built on top of the protocol rather than inside it.

In practice

How ghost aircraft are actually detected

Because nothing in the message itself can be cryptographically checked, every practical detection approach is indirect: it looks for contradictions between what the message claims and what physics, statistics or other receivers say should be true. AeroScope and comparable systems combine several of these checks rather than relying on any single one:

None of these checks are proof on their own. They are evidence that accumulates. AeroScope's approach, described in more detail on the ADS-B spoofing detection page, is to run several independent checks and flag an aircraft only when more than one disagrees with the claimed track, rather than reacting to any single anomalous reading.

Be honest about the limits

A well-constructed spoof can pass

It needs to be said plainly: a sufficiently careful ghost track, one that reports physically plausible kinematics, internally consistent integrity fields, and either avoids being seen by a corroborating independent receiver or is engineered to be consistent across receivers, can pass every check listed above. Detection here is a matter of raising the cost and skill required to fake a track convincingly, not a guarantee that every fake will be caught. This is true of every public or crowdsourced ADS-B monitoring system, not a limitation unique to AeroScope. Systems with an independent position reference, such as multilateration or satellite-based verification, can catch classes of spoofing that pure ADS-B analysis cannot, and AeroScope does not have that independent reference; see known limitations.

What to conclude

If you see an odd track

Treat an odd-looking track as a reason to look closer, not as proof of anything. The overwhelming majority of strange-looking tracks have mundane causes: multipath reflection off terrain or buildings corrupting a position fix, a decoding error on a weak signal that a receiver failed to reject, a test or maintenance transmission, or simply a real aircraft doing something genuinely unusual, such as a go-around, a holding pattern or a photography flight. A small minority are real spoofing, jamming-induced degradation, or fabricated ghost tracks. AeroScope's job is to surface the evidence, the integrity fields, the cross-source agreement, the physics checks, so you can judge for yourself, rather than to assert a verdict it cannot fully back up.

Questions

Common questions

What is a ghost aircraft in ADS-B?
A ghost aircraft is an ADS-B track that shows up on a map or receiver with no real aircraft behind it. It is either fabricated from scratch by a transmitter that was never attached to any airframe, or it is a real aircraft's identity replayed or altered so the resulting track no longer matches anything actually flying.
Can ADS-B messages be authenticated?
No. ADS-B, as deployed today, has no cryptographic authentication or encryption. Any radio transmitter capable of producing a correctly formatted 1090ES or UAT message can broadcast a position, altitude and identity that a receiver has no built-in way to verify came from a real aircraft.
How is a ghost aircraft detected?
In practice, detection is inferential rather than definitive: checking whether the reported kinematics are physically plausible for the claimed aircraft type, whether the integrity fields (NIC, NACp, SIL) are internally consistent with the claimed accuracy, whether multiple independent receivers agree on the same position, and whether a Kalman filter's innovation (the gap between predicted and reported position) stays within a normal range.
What should I conclude if I see an odd track?
Treat it as a prompt to look closer, not as proof of anything. Most odd tracks have mundane explanations: multipath reception, a decoding glitch, a test transmission, or an aircraft genuinely doing something unusual. A small number are real spoofing or ghost injection, and a well constructed spoof can pass every automated check available to a public tracker.