kimo

Airspace awareness from open ADS-B data

Open ADS-B data gives you a near-real-time picture of most cooperative air traffic: aircraft broadcast their own position, velocity, identity and navigation quality on 1090 MHz, and volunteer receiver networks collect those broadcasts so anyone can analyze them. What it cannot give you is a complete or authenticated picture, so a useful air picture fuses ADS-B with multilateration, reference data and clear confidence labels instead of treating every dot on the map as ground truth.

Hugo Lefèvre
Aviation data analyst12 min read7 sources

For most of aviation history, "who is flying over this region right now?" was a question only air navigation service providers could answer well. Today a researcher with a laptop can query open ADS-B data for most of the commercial traffic over Europe or North America. That shift is real and useful for safety research, crisis response, environmental studies and newsroom verification. It is also easy to over-trust. This post explains how ADS-B works, what open networks can and cannot tell you, and how we model a fused air picture in Kimo Defense Intelligence.

§01What is ADS-B and how does it work?

ADS-B (Automatic Dependent Surveillance–Broadcast) is a surveillance technique in which an aircraft determines its own position, usually from GNSS, and broadcasts it together with other state data. It is automatic because no pilot or controller input is needed, dependent because it depends on the aircraft's own navigation system, and broadcast because anyone with a receiver can listen. On the widely used 1090 MHz Extended Squitter link, each message is a 112-bit frame carrying a 24-bit ICAO aircraft address and a 56-bit payload whose first five bits, the type code, say what the message contains: identification, surface position, airborne position, velocity or status1.

Broadcast rates differ by message type. Under ADS-B version 2, airborne position and airborne velocity are each sent at about 2 Hz, identification at 0.2 Hz in flight, and aircraft status jumps from 0.2 Hz to 1.25 Hz when the squawk code changes1. That last detail matters for alerting: a change of transponder code is announced more frequently, so an emergency code reaches receivers quickly.

Message group (type code)What it carriesNominal rate (v2, airborne)
1–4: IdentificationCallsign and emitter category0.2 Hz
9–18: Airborne position (baro altitude)CPR-encoded latitude/longitude, barometric altitude2 Hz
19: Airborne velocityGround speed, track, vertical rate2 Hz
20–22: Airborne position (GNSS height)Position with geometric altitude2 Hz
28: Aircraft statusEmergency/priority status, squawk0.2 Hz, 1.25 Hz on change
31: Operational statusVersion, NIC/NAC/SIL supplements0.4 Hz, 1.25 Hz on change
Selected ADS-B type codes and broadcast rates, summarized from Junzi Sun, The 1090 Megahertz Riddle (source 1).

Every position also comes with quality indicators. NIC (Navigation Integrity Category) expresses a containment radius the aircraft is confident its true position lies within, and NACp (Navigation Accuracy Category for position) expresses a 95% accuracy bound; NACp 9, for example, means the estimated position uncertainty is under 30 m2. These fields are easy to ignore when you only want dots on a map. They turn out to be the most interesting part of the feed, as we explain in Mapping GNSS interference with ADS-B quality indicators.

§02What can open receiver networks actually see?

A single ADS-B receiver is a small radio, an antenna and a decoder. Networks aggregate thousands of them. The OpenSky Network, built by academic researchers, started as a sensor network in Central Europe; its founding paper reported coverage of roughly 720,000 km² and more than 30% of European commercial air traffic after about two years of operation4. It has grown considerably since, but the principle holds: you see what volunteers' antennas can hear.

OpenSky exposes this data as state vectors, one row per aircraft per time step, through a public REST API. A state vector includes the ICAO24 address, callsign, longitude, latitude, barometric and geometric altitude, velocity, track, vertical rate, squawk, an SPI flag, an on_ground flag and a position_source that tells you whether the position came from ADS-B, ASTERIX, MLAT or FLARM3. Anonymous users get the most recent vectors at 10-second resolution with a daily credit quota; authenticated users get 5-second resolution and up to an hour of history3.

112 bits
per 1090ES ADS-B frame
~2 Hz
airborne position broadcast rate
24-bit
ICAO address identifies the airframe
10 s
anonymous OpenSky state-vector resolution

§03What open ADS-B data cannot tell you

Good analysis starts with honest limits. We keep this list on the wall of our defense team:

  • Absence is not evidence. If an aircraft disappears, the first suspects are receiver coverage, terrain and low altitude, not anything dramatic. Coverage thins out over oceans, mountains and sparsely populated areas.
  • Not every aircraft broadcasts. Equipage rules vary by airspace and aircraft type, and some aircraft legitimately fly without ADS-B Out. An open air picture is a picture of cooperative traffic.
  • Messages are unauthenticated. ADS-B carries no cryptographic protection; the security literature has long documented that messages can be spoofed or injected5. Treat implausible tracks as data-quality events first.
  • Positions are only as good as the aircraft's navigation. When GNSS is degraded, ADS-B positions degrade with it, which is exactly what NIC and NACp reveal2.
  • Identity is partial. The ICAO24 address identifies a transponder, not a flight plan. Callsigns may be missing or reused; enrichment requires reference data.

§04How multilateration and reference data fill the gaps

Some aircraft carry Mode S transponders that reply to radar interrogations but do not broadcast their position; Mode S adds altitude reporting and data exchange to classic secondary-radar replies6. When enough time-synchronized receivers (typically four or more) hear the same reply, the network can compute a position from the time difference of arrival. That technique, multilateration (MLAT), is why OpenSky labels some positions with position_source = 23. MLAT positions are independent of the aircraft's own GNSS, which makes them a useful cross-check, but they need dense receiver geometry and are usually less precise.

Reference layers turn raw tracks into context: airport and airspace boundaries, terrain, OpenStreetMap infrastructure for points of interest, aircraft registry data for type and operator, and the regulatory meaning of transponder codes. None of these are glamorous. All of them are required to answer "is this normal?"

§05How to fuse ADS-B into one air picture

ADS-B data pipelineAircraft broadcasts are collected by receivers (and MLAT), delivered as a feed, modeled in Kimo, and served to the map and alerts.1090 MHz · Mode S / ADS-BGround receiversposition · altitude · velocity · IDMLAT locates non-ADS-B Mode SOpenSky NetworkOSFeed aggregatoropen network · own RXADS-B Air TrafficABKimo ingestdecode · dedupetracks · smoothedLive maptracks · trailsAlerts7500·7600·7700GNSS layerNIC / NACpBridge mode keeps raw feeds on your own servers
Figure.Aircraft broadcasts are collected by receivers (and MLAT), delivered as a feed, modeled in Kimo, and served to the map and alerts.

Scroll sideways to see the full diagram.

We think of fusion as four modeling steps, each of which produces a table you can query on its own. This is the structure of the Airspace watch template and of the step-by-step ADS-B ingestion guide.

  1. Step 1:

    Normalize state vectors

    Convert every feed (OpenSky, your own receivers via ADS-B, a Kafka topic) into one schema: icao24, ts, lat, lon, alt_baro_m, alt_geo_m, gs_ms, track_deg, squawk, position_source, nic, nacp. Units in SI, timestamps in UTC.

  2. Step 2:

    Deduplicate and order

    Multiple receivers hear the same message. Keep one row per aircraft per time bucket, preferring ADS-B over MLAT and fresher over staler, and drop vectors whose implied speed between consecutive points is physically implausible.

  3. Step 3:

    Segment into flights and tracks

    Split each aircraft's timeline into flights using ground/air transitions and gaps longer than a threshold (we default to 15 minutes airborne). A flight is the unit analysts reason about.

  4. Step 4:

    Score confidence and enrich

    Attach coverage (how many receivers heard it), source type, quality indicators and reference context. The output is a tracks model that maps, alerts and Ask Kimo all share.

Flag implausible jumps before they reach the map
sql
select icao24, ts, lat, lon,
       haversine_km(lat, lon, prev_lat, prev_lon)
         / nullif(extract(epoch from ts - prev_ts), 0) * 3600 as implied_kmh
from (
  select *,
         lag(lat) over w as prev_lat,
         lag(lon) over w as prev_lon,
         lag(ts)  over w as prev_ts
  from state_vectors
  window w as (partition by icao24 order by ts)
) v
where haversine_km(lat, lon, prev_lat, prev_lon)
      / nullif(extract(epoch from ts - prev_ts), 0) * 3600 > 1500;

The 1,500 km/h ceiling is a deliberately generous plausibility bound for civil traffic, not a physics constant; tune it per region and aircraft category. Rows that fail it are not deleted. They are routed to a data-quality view, because a burst of impossible jumps in one area is itself a signal worth investigating.

Share of tracked positions by source over a day
  • ADS-B
  • MLAT
Figure. Illustrative data: simulated regional feed, hourly share of positions by source. In this simulated feed the MLAT share rises overnight as the traffic mix changes.

§06What is an open-data air picture good for?

Used with its limits in mind, a fused air picture supports a wide range of legitimate work:

  • Safety and resilience monitoring: emergency squawks, unusual descents, and regional GNSS degradation. EASA notes that GNSS interference is increasing, particularly in regions surrounding conflict zones, and around the Mediterranean, the Black Sea, the Middle East, the Baltic Sea and the Arctic7.
  • Crisis and disaster response: which airports are still receiving traffic after a storm, where medical and firefighting flights are operating.
  • Research and journalism: verifying claims about airspace closures or diversions with reproducible queries.
  • Operations analytics: holding patterns, diversions and delay propagation for airports, operators and regulators.

In Kimo, the Airspace view renders the tracks model on a map with confidence styling, and Alerts run rules against the same model. Because both sit on one definition, the number in the alert is the number on the map. For alert design, read Emergency squawks and flight anomalies; for the full methodology and limits, the Airspace Awareness from Open Data whitepaper.

§07Where should the air picture live?

Many teams that collect their own receiver data cannot ship it to a third-party cloud. With Kimo Bridge, the receiver database stays on your server and Kimo queries it live through an outbound-only tunnel; with Cloud mode, Kimo keeps a synced copy for long history. Fully disconnected environments can run Kimo air-gapped, as described in the on-premise docs.

Connectors used to build a fused air picture in Kimo.

Frequently asked questions

Is ADS-B data public?

ADS-B messages are broadcast unencrypted on open frequencies, so anyone with a receiver can decode them. Networks such as OpenSky make aggregated data available for research under their own terms of use, which you should read before building on them.

How accurate are ADS-B positions?

Usually very accurate, because they come from the aircraft's GNSS receiver. Each position is accompanied by NACp and NIC values that state its accuracy and integrity; when GNSS is degraded those values drop, and you should treat the position with caution.

Why do aircraft disappear from ADS-B maps?

Most often because no receiver can hear them: low altitude, terrain, distance from the nearest antenna or ocean areas. Less often, the transponder is off or the aircraft is not ADS-B equipped. A gap is a coverage question before it is anything else.

What is the difference between ADS-B and MLAT positions?

ADS-B positions are reported by the aircraft itself. MLAT positions are computed by the receiver network from the arrival times of a transponder signal at several receivers. MLAT is independent of the aircraft's navigation system but needs good receiver geometry and is usually less precise.

Can I use Kimo without sending receiver data to the cloud?

Yes. Kimo Bridge lets Kimo query your receiver database live without storing it, and Kimo can also run fully on-premise or air-gapped.

Sources

7 references
  1. The 1090 Megahertz Riddle: ADS-B basics (opens in a new tab)
    Junzi Sun, TU Delft (mode-s.org)mode-s.org

    Frame structure, type codes and broadcast rates.

  2. The 1090 Megahertz Riddle: Uncertainty, accuracy and integrity (opens in a new tab)
    Junzi Sun, TU Delft (mode-s.org)mode-s.org

    NIC, NACp and SIL definitions and tables.

  3. OpenSky REST API documentation (opens in a new tab)
    OpenSky Networkopenskynetwork.github.io

    State vector fields, position_source values, resolution and credits.

  4. Bringing up OpenSky: A large-scale ADS-B sensor network for research (opens in a new tab)
    Schäfer, Strohmeier, Lenders, Martinovic, Wilhelm — IPSN 20142014opensky-network.org

    720,000 km² coverage and more than 30% of European commercial traffic after almost two years of operation.

  5. On the Security of the Automatic Dependent Surveillance-Broadcast Protocol (opens in a new tab)
    Strohmeier, Lenders, Martinovic — IEEE Communications Surveys & Tutorials (arXiv 1307.3664)2015arxiv.org

    Lack of security measures in ADS-B.

  6. Transponder (opens in a new tab)
    SKYbrary Aviation Safetyskybrary.aero

    Transponder modes and special codes.

  7. Global Navigation Satellite System outages and alterations (opens in a new tab)
    EASAeasa.europa.eu

    Regions affected by GNSS interference.

External sources were accessed at the time of writing. Kimo product details, customers and figures in examples are illustrative unless a source is cited.

  • #ADS-B
  • #Airspace
  • #OSINT
Found this useful? Pass it on.
Written by
Hugo Lefèvre
Aviation data analyst at Kimo · 2 articles

Writes about ADS-B, Airspace, OSINT, GNSS.

Kimo people and customers mentioned are illustrative; example charts use simulated data unless a source is cited. All aircraft data shown in Kimo is simulated.

Put it to work

Go deeper

Whitepaper

Airspace Awareness from Open Data

ADS-B, Mode-S and GNSS interference: what open aviation data can reveal, its limits, and how to fuse it responsibly.

32 pages
Template

Airspace watch

Live air picture with emergency squawks, loitering and geofence alerts.

4 min setup
Live demo

Open Airspace

Tracks, emergency squawks and a GNSS-interference map on a simulated feed.

Simulated data · no sign-up

All resources
GuideAdvanced
Defense

Ingest ADS-B feeds into Kimo

Connect a receiver network or OpenSky, normalize state vectors, and model flights and tracks.

Hugo Lefèvre
12 min read
Whitepaper
Defense

Airspace Awareness from Open Data

ADS-B, Mode-S and GNSS interference: what open aviation data can reveal, its limits, and how to fuse it responsibly.

Hugo Lefèvre
32 pages

Airspace awareness from open data.

Fuse ADS-B, AIS and OSINT feeds on your own infrastructure. The demo runs entirely on simulated data.