WHERE TO LOOK FIRST

Threat & attention scoring

When dozens of aircraft are overhead, the question is not "where are they" but "which one deserves my attention first." AeroScope answers it with a transparent 0–100 score built from eight weighted, rule-based factors, and it always shows its working. It is a ranker, not a verdict.

Quick answer. AeroScope ranks which aircraft deserve attention first with a transparent 0–100 score from eight weighted, rule-based factors: emergency squawk, military hex allocation, observer proximity, altitude and speed anomalies, loitering or orbit patterns, ICAO integrity-check failures, unregistered identity and drone-like kinematics. Every score shows its contributing factors, so it is an explainable ranker, not a black-box verdict.
Shown working

An attention-ranker, demonstrated

The needle below cycles through example aircraft. In the live app it reflects real broadcasts, recomputed every cycle, with the contributing factors always displayed beside it.

0–40  Routine traffic, minor or no anomalies.
41–60  Moderate, multiple factors present.
61–100  Elevated, several strong indicators agree.

A high score means "look here first," not "this aircraft is hostile."

Military ICAO hex rangeweight 20
Squawk code (7500 / 7600 / 7700)weight 18
Signal integrity (NIC / NACp / SIL)weight 14
Flight-envelope anomalyweight 12
Missing callsign / registrationweight 10
Restricted-airspace proximityweight 10
Pattern-of-life classificationweight 10
Signal quality / message rateweight 6
Design principles

Why it's rule-based and explainable on purpose

🔍

Every point is traceable

The score is a weighted sum of named factors, so each aircraft's number decomposes back into exactly which signals fired and by how much. No black box.

⚖️

It ranks, it doesn't accuse

The output sorts a busy list so an operator looks at the right aircraft first. A high score is a prompt for human judgement, never an automated allegation.

🧩

Separate from detection

The attention score is distinct from the consensus anomaly detectors. Scoring decides order; detection decides whether a specific anomaly is real (≥2 detectors must agree).

An honest boundary. AeroScope does not classify intent. It cannot tell you a flight is hostile, lost, or benign, only that, by transparent rules, it is statistically unusual enough to merit a second look. The judgement stays with you.
Worked example

How a score is actually assembled

Scores are additive and every contribution is displayed next to the aircraft, so the arithmetic can always be checked. Consider a real pattern: an aircraft with an ICAO address inside a known military block, flying a racetrack orbit at 22,000 ft roughly 15 nautical miles from your position, with no filed callsign.

ObservationContribution
ICAO hex sits in an allocated military blockLarge. This is the single heaviest factor.
No callsign or registration resolvesModerate. Common for state aircraft, so it corroborates rather than proves.
Racetrack orbit sustained over timeModerate. Distinguishes loitering from transit.
Within tens of nautical miles of the observerSmall and distance-scaled. Proximity raises relevance, not menace.
Integrity fields consistent, altitude and speed plausibleNothing added. The broadcast is internally coherent.

The result lands in the elevated band, and the honest interpretation is "a state aircraft is loitering nearby". That is very often an air-refuelling track, a training area or a survey task. The score has done its job by moving one aircraft to the top of a list of two hundred. It has not made a judgement about intent, and it should not be read as one.

Design

Why weights, and why these weights

Three design choices matter more than the specific numbers.

Rules, not a learned model. A trained classifier could likely rank aircraft slightly better on a benchmark. It could not tell you why it ranked one first, and it would drift silently as traffic patterns changed. Every factor here maps to a stated rule you can disagree with. That trade, accepting a little accuracy for full auditability, is deliberate and is the same reasoning behind the torch-free anomaly stack.

Weights reflect discriminating power, not danger. A military hex allocation scores highly because it is rare and unambiguous, not because military aircraft are dangerous. Emergency squawks score highly because they are unambiguous declarations by the crew. Proximity scores low because almost everything is near someone.

Corroboration beats any single signal. The scale is built so that no lone factor reaches the elevated band by itself. Several independent indicators have to agree, which is the same consensus principle used in spoofing detection.

Boundaries

What the score is not

FAQ

Frequently asked questions

Is the threat score an accusation that an aircraft is dangerous?
No. It is a 0–100 attention-ranker that sorts a busy list so an operator knows where to look first. It is computed from eight transparent, weighted factors, all of which are shown. A high score means "unusual, worth a look," not "hostile."
What factors go into the score?
Eight weighted rule-based factors: military ICAO hex range, emergency squawk (7500/7600/7700), signal integrity (NIC/NACp/SIL), flight-envelope anomaly, missing callsign or registration, restricted-airspace proximity, pattern-of-life classification, and signal quality / message rate.
How is scoring different from anomaly detection?
Scoring decides the order of attention from explainable rules. Anomaly detection is a separate layer of six independent detectors (River, IsolationForest, pykalman, OpenAP, stumpy, PyOD) that only flags something when at least two agree. One ranks; the other confirms.
Does a high score mean the aircraft is spoofed?
Not necessarily. Spoofing has its own integrity-specific checks. A high attention score can come from many causes, a military hex, an emergency squawk, an envelope anomaly, so it points you to an aircraft worth examining, where the integrity and detection layers then help explain why.
How does AeroScope calculate its threat score?
It sums eight weighted, rule-based factors into a 0 to 100 value: military ICAO hex allocation, emergency squawk, signal integrity failures, flight-envelope anomalies, missing callsign or registration, restricted-airspace proximity, loitering or orbit patterns and drone-like kinematics. Every contributing factor is displayed beside the aircraft so the arithmetic can be checked.
Does a high attention score mean an aircraft is dangerous?
No. It means several independent signals agree that this aircraft is unusual enough to look at first. The most common explanations for a high score are entirely routine, such as a military tanker flying a refuelling racetrack or an aircraft declaring a medical emergency.
Why use weighted rules instead of machine learning for scoring?
A learned model might rank marginally better on a benchmark but could not explain why it ranked an aircraft first, and it would drift silently as traffic patterns changed. Rules trade a little accuracy for full auditability, which matters more when the output influences how someone interprets their sky.
Can one factor alone produce a high score?
No. The scale is deliberately built so no single factor reaches the elevated band on its own. Several independent indicators have to agree, which suppresses false alarms from any one noisy signal.