kimo
WhitepaperKimo Defense

Airspace Awareness from Open Data

ADS-B, Mode-S and GNSS interference: what open aviation data can reveal, its limits, and how to fuse it responsibly.

A practical, sourced guide to building civil airspace awareness from open aviation data: how ADS-B (1090ES and UAT), Mode S and multilateration work; how volunteer receiver networks such as the OpenSky Network collect them; which fields are trustworthy; how emergency squawks and navigation-quality degradation become alerts and interference maps; how to fuse tracks with weather, NOTAMs and reference data; and the privacy, licensing and ethical boundaries that apply. It closes with a reference architecture, a maturity model and a candid section on methodology and limits.

Pages
32
Read time
25 min
Chapters
14
Sources
15

Get the PDF

A print-ready edition (32 pages) with cover, contents and every source URL.

No spam: we use these details to send you this report and nothing else without your consent. Prefer not to share them? The full report is free to read online.

Read online

The full report

Prefer a PDF?

§01Executive summary

Most commercial aircraft now broadcast their own position, velocity, identity and navigation quality several times per second, in the clear, on frequencies anyone can receive. In the United States, aircraft operating in the airspace defined in 14 CFR 91.225 have been required to carry ADS-B Out since January 1, 2020, and must transmit at all times unless the FAA or ATC authorizes otherwise2. Volunteer and research receiver networks collect these broadcasts at scale; the OpenSky Network was founded precisely because large-scale raw ADS-B data had previously been accessible only to "a few closed industrial and governmental groups"1.

That makes open aviation data one of the richest public sensor feeds in existence. For a civil safety team it supports three high-value use cases: a situational air picture (who is flying where, with what confidence), anomaly alerting (emergency transponder codes, unusual altitude profiles, geofence entries), and GNSS interference mapping (where aircraft report degraded satellite-navigation quality). The third has moved from research curiosity to operational concern: EASA reports that jamming and spoofing have increased since February 2022, particularly around conflict zones, and keeps a Safety Information Bulletin on the topic, now in its fourth revision9. IATA data cited by EASA shows GPS signal-loss events rising 220% between 2021 and 202410.

2 Hz
Nominal ADS-B airborne position rate (v2)
112 bits
Length of one 1090 MHz Extended Squitter frame
+220%
GPS signal-loss events, 2021–2024 (IATA via EASA)
60%
Share of daily traffic affected on peak RFI days in one 2022 study area

The same openness creates the limits. ADS-B positions are self-reported and the protocol has an "inherent lack of security measures"6. Coverage depends on where receivers happen to be installed. Some aircraft, including state aircraft on sensitive missions, are legitimately authorized not to transmit2. And individual flights belong to people and companies with privacy interests that regulators recognize1314. Our recommendations, developed in the chapters below, are:

  1. Treat the air picture as an estimate with explicit confidence, not as ground truth. Carry position source, receiver count and navigation-quality fields through every model and show them in every view.
  2. Model coverage as data. Compute where your receivers can hear, per altitude band and per hour, and render gaps as gaps.
  3. Aggregate before you alert. A single aircraft with a degraded NACp is noise; many aircraft degrading in the same cell and time window is a signal.
  4. Keep rules few, debounced and explained, with an owner and a review cadence for each, and measure alert precision as a first-class metric.
  5. Govern the data like personal data: purpose-limited, minimized, retained only as long as necessary, with respect for privacy programs and data licenses.
  6. Never use open data as the sole basis for an operational decision. Its job is to direct attention and corroborate, not to replace certified surveillance or official reporting channels.

§02What is open aviation data, and where does it come from?

"Open aviation data" in this paper means signals transmitted by aircraft for cooperative surveillance that can be received with commodity hardware, plus the public reference data needed to interpret them. Three techniques matter: ADS-B, Mode S, and multilateration (MLAT). They are often conflated in flight-tracking apps, but their provenance and trustworthiness differ, and a serious pipeline keeps them apart.

ADS-B: the aircraft tells you where it is

In ADS-B, an aircraft determines its own position, normally from GNSS, and broadcasts it periodically along with velocity, identification, status and an uncertainty level; position is typically sent twice per second, while status and intent are event-driven1. On the 1090 MHz Extended Squitter link, each frame is 112 bits: a 5-bit downlink format, a 24-bit ICAO aircraft address, a 56-bit payload and 24 parity bits4. Downlink Format 17 is used by Mode S transponders; Downlink Format 18 is used by non-transponder ADS-B equipment and TIS-B ground rebroadcasts4, a distinction worth preserving because a DF18 TIS-B target is a ground system relaying radar-derived data, not the aircraft speaking.

There are two ADS-B links in practice. 1090ES is used worldwide. In the United States, aircraft may alternatively use UAT on 978 MHz below 18,000 ft MSL, while operations in Class A airspace require equipment meeting the 1090 MHz standard (RTCA DO-260B, or the newer DO-260C)2. For an analyst this means a 1090-only receiver in the United States will systematically miss part of the general aviation fleet at lower altitudes, a coverage bias that has nothing to do with geography.

Mode S: interrogated replies with less context

Mode S is the selective-addressing secondary surveillance system on which 1090ES is built. Its uplink uses 1030 MHz and its downlink 1090 MHz1. Ground radars interrogate aircraft and receive replies containing identity, altitude and, depending on the interrogation, other parameters. A passive receiver hears these replies too, but a reply to someone else's radar carries no position: you learn that an address exists and what altitude it reports, not where it is. Mode S-only aircraft therefore appear in raw message counts but not on maps unless something else locates them.

Multilateration: locating the transmitter, not trusting it

Multilateration computes an aircraft's position from the time difference of arrival (TDOA) of the same transmission at several synchronized receivers. Each pair of receivers constrains the aircraft to a hyperboloid; with four receivers a 3D position can be estimated, and with three a 2D position if altitude is known from another source5. Because it uses transmissions aircraft already make, MLAT requires no airborne changes5. Its great virtue for open-data work is independence: it locates the transmitter physically instead of believing the position the transmitter reports, which is why the security literature lists it among plausibility-checking techniques6. Its cost is density: you need several well-synchronized receivers with line of sight to the same aircraft.

SourcePosition fromStrengthsMain caveats
ADS-B 1090ES (DF17)Aircraft GNSS, self-reportedHigh rate, rich fields incl. NIC/NACp, squawk, callsignUnauthenticated; inherits GNSS errors; not every aircraft equipped
ADS-B / TIS-B (DF18)Non-transponder device or ground rebroadcastFills gaps for some trafficMay duplicate targets; ground-derived positions
UAT (978 MHz, US)Aircraft GNSS, self-reportedCommon in US general aviation below Class ANeeds a separate receiver; regional
Mode S repliesNone (identity, altitude)Reveals presence of non-ADS-B aircraftNo position without MLAT
MLATTDOA across receiversIndependent of aircraft-reported positionNeeds ≥3–4 synchronized receivers in view; lower rate
Open aviation surveillance sources compared. Sources: Schäfer et al. 2014; 14 CFR 91.225; Sun, The 1090 Megahertz Riddle; EUROCONTROL/NLR WAM report.

§03How do open receiver networks work, and where are they blind?

A receiver is an antenna, a radio front end and a decoder. A network is many of them streaming decoded messages, with timestamps and receiver identifiers, to a central service. The OpenSky Network began with 11 sensors hosted by volunteers in Central Europe; its founding paper reported a sensing range of about 720,000 km² and capture of more than 30% of European commercial air traffic after roughly two years1. The network stores, alongside each message, the receiver's identifier, a high-resolution reception timestamp and the raw frame1, which is what makes later research such as MLAT and interference studies possible.

ADS-B data pipelineFrom broadcast to decision support: aircraft transmit; receivers and MLAT servers decode and timestamp; a feed delivers state vectors; Kimo models flights, coverage and quality; analysts see maps and alerts with confidence attached.1090 MHz · Mode S / ADS-BGround receiversposition · altitude · velocity · IDMLAT locates non-ADS-B Mode SOpenSky NetworkOSFeed aggregatoropen network · own RXADS-B Air TrafficABKimo ingestdecode · dedupetracks · smoothedLive maptracks · trailsAlerts7500·7600·7700GNSS layerNIC / NACpBridge mode keeps raw feeds on your own servers
Figure.From broadcast to decision support: aircraft transmit; receivers and MLAT servers decode and timestamp; a feed delivers state vectors; Kimo models flights, coverage and quality; analysts see maps and alerts with confidence attached.

Scroll sideways to see the full diagram.

Four kinds of blindness

  • Geographic blindness. Receivers are ground-based and line-of-sight. Oceans, deserts, mountains and conflict areas are thin or empty. A 2022 interference study explicitly notes that large parts of its study area over the Black Sea had limited or no ADS-B coverage11.
  • Altitude blindness. Line of sight shrinks with altitude: a receiver that hears airliners at cruise 300 km away may not hear a helicopter 30 km away behind a ridge. Low-level traffic is systematically under-observed.
  • Equipment blindness. Aircraft that are not required to carry ADS-B Out, or that use UAT where you only receive 1090 MHz, are absent or present only as Mode S replies.
  • Authorized silence. US rules allow the FAA to authorize aircraft on sensitive government missions not to transmit, and ATC to direct transmissions off2. Absence of a track is therefore never evidence of absence of an aircraft.

Network behavior also changes over time. Volunteers move, antennas fail, and new sensors appear. A coverage model must be recomputed regularly, and any trend analysis (more emergencies this year, more interference this month) must normalize by coverage, ideally by counting observed flights per cell as the denominator. The 2014 OpenSky paper illustrates a related subtlety: it splits messages into flights using a ten-minute silence threshold, a pragmatic tradeoff that can wrongly merge a quick turnaround or split a flight that leaves and re-enters coverage1. Any derived "flight" is a modeling choice, and the choice should be documented.

§04Data quality: which fields can you trust?

Trust in open aviation data is field-specific. Some fields are transmitted with integrity metadata; others are typed in by crews; some are inferred by the network. The table below is the trust map we use when modeling state vectors in Kimo.

FieldOriginTrust levelHow to use it
ICAO 24-bit addressTransponder configurationMedium: stable per airframe but reprogrammablePrimary key for tracks; never assume it maps to a public registry entry
Position (lat/lon)Aircraft navigation systemQualified by NIC/NACpAlways carry the quality fields with it
Barometric altitudeAir data, 25 ft steps on 1090ESHigh for vertical profileNot the same as geometric height; do not mix the two
Velocity, track, vertical rateAircraft sensorsMedium–highUse for plausibility checks against position deltas
CallsignEntered by crew or operatorMediumCan change in flight or be blank; never a unique key
Squawk (Mode A code)Selected by crewMedium: momentary mis-selection happensDebounce before alerting
NIC / NACpAvionics integrity and accuracy estimatesHigh as indicators, equipment-dependentAggregate across aircraft before drawing conclusions
Origin countryInferred from address blockLow for operationsContext only
Field-level trust map for ADS-B state vectors. Sources: Schäfer et al. 2014 (altitude resolution, NAC behavior); Sun, The 1090 Megahertz Riddle (address reprogrammability); FAA AIM 4-1-20 (code selection).

Three quality problems deserve special attention. First, not every position is GNSS-derived: the OpenSky founders observed that some aircraft broadcasting positions are not even equipped with GNSS and use less accurate means, which "can lead to large errors"1. Second, quality indicators were not always populated: in 2014 the same authors found the navigation-accuracy field set to "unknown" on most transponders1. The US performance rule has since raised the floor (NACp better than 0.05 NM and NIC better than 0.2 NM for compliant aircraft3), but international and older fleets vary. Third, the address is not an identity: the 24-bit ICAO address uniquely identifies a transponder but can be reprogrammed4, and privacy programs deliberately issue alternate addresses13.

Finally, ADS-B offers no cryptographic authentication. The academic literature has described this lack of security measures for over a decade6. In practice it means every pipeline should run plausibility checks: kinematic consistency (does the next position follow from the last one at the reported speed?), multi-receiver consistency (do several receivers hear the same target?), and MLAT cross-checks where receiver density allows. Tracks failing those checks are not necessarily malicious, since decoding errors and multipath are far more common, but they should be flagged as low confidence rather than silently drawn.

Minimum data-quality controls for a state-vector model

  • Deduplicate by (address, timestamp, position) across receivers before counting anything.
  • Keep DF17 and DF18/TIS-B targets distinguishable; never double count a rebroadcast.
  • Carry position source (ADS-B, MLAT, other) on every row.
  • Reject or flag positions implying impossible speeds between consecutive fixes.
  • Store barometric and geometric altitude in separate columns with units.
  • Keep NIC and NACp with the last known value and its age.
  • Compute a per-cell, per-hour coverage table from your own receptions.
  • Version your flight-segmentation rule and record which version built each flight.

§05Emergency squawks and anomaly signals

A squawk code is the four-digit Mode A code selected on the transponder. Three codes carry special meaning in civil aviation, and automated ATC facilities are built to flag them. The FAA's Aeronautical Information Manual instructs pilots to select 7700 for emergencies ("SQUAWK MAYDAY")7, 7600 after losing two-way radio capability8, and describes 7500 as the hijack code7. It also warns pilots to avoid inadvertently selecting 7500, 7600 or 7700 when changing codes, because doing so causes "momentary false alarms at automated ground facilities"; codes in the 7600–7677 and 7700–7777 series trigger special indicators, while only the non-discrete 7500 is decoded as a hijack7.

CodeMeaningWhat an open-data alert should do
7700General emergencyRaise high-priority alert after persistence check; attach track history, altitude profile, nearest aerodromes, weather
7600Two-way radio communication failureRaise alert; expect normal-looking trajectory; annotate with lost-comms context
7500Unlawful interference (non-discrete code only)Raise alert to a restricted audience; avoid public broadcast; defer to authorities
7601–7677, 7701–7777Discrete codes in emergency seriesTreat as emergency-series per AIM; verify locally applicable meaning
Emergency-series transponder codes and recommended handling. Source: FAA Aeronautical Information Manual 4-1-20, 4-1-21 and 6-4-2.

The AIM's warning about momentary false alarms translates directly into alert design: require the code to persist across several messages or seconds before alerting, and suppress alerts for a code seen in a single frame from a single receiver. Note too that open-data emergency alerts are observations, not reports. Air traffic control has the radio, the flight plan and the crew; an open-data team has a broadcast. The right response to a 7700 in Kimo is to bring context together quickly for someone with a legitimate interest (an airport operator, a civil protection duty officer, a newsroom verifying a story) and to avoid amplifying anything about a 7500 event publicly.

Other anomaly signals worth modeling

  • Unusual altitude profiles: rapid descents outside approach phases, prolonged level-offs at unusual altitudes, or repeated climbs and descents.
  • Holding and loitering: sustained turning in a confined area, which is routine near busy airports and noteworthy elsewhere.
  • Geofence entries: civil safety zones such as temporary flight restrictions around disasters or major events, defined from official notices.
  • Data anomalies: sudden position jumps, quality-field collapse, or an address appearing in two places at once. These are often reception artifacts, and they are also the first symptoms of navigation interference.

Each of these needs a baseline. "Unusual" is relative to the route, the airport and the hour. The companion guide Airspace alerting rules that analysts trust gives concrete rule definitions, thresholds and suppression windows.

§06How can aircraft data reveal GNSS interference?

GNSS interference is any radio-frequency effect that prevents a satellite-navigation receiver from computing a correct position. EASA distinguishes jamming, which blocks the signal, from spoofing, which feeds counterfeit signals to deceive receivers, and lists symptoms such as position discrepancies, time shifts and spurious terrain-warning alerts9. Its bulletin treats the issue as a safety matter for operators and air navigation service providers, recommending that ANSPs collect and communicate information on GNSS degradation and keep conventional navigation aids available9.

Aircraft are, in effect, a dense network of GNSS receivers flying through the sky and reporting how confident they are in their position. When interference denies GNSS, the navigation-quality fields they broadcast degrade. Researchers have shown that NACp drops from values above 8 to 0 when aircraft are affected by radio-frequency interference, and recovers when they leave the area11. NIC is carried in every airborne position message (every 0.4–0.6 s) while NACp travels in the less frequent operational status message (every 2.4–2.6 s), which is why some studies prefer NIC as a per-position proxy for GNSS reception quality12.

Mapping GNSS interference from ADS-B quality fieldsAircraft-reported NIC/NACp degradation is aggregated into hexagonal cells per time window; cells where a meaningful share of aircraft report degraded quality form a daily interference layer, always read alongside coverage.Position reports (simulated)AircraftNICNACpNavSIM101810okSIM20279okSIM30300lowSIM404810okSIM50524lowSIM60679okFlag degradedNIC or NACp below thresholdAggregate to hexes% degraded per cell per dayLow< 2% aircraftMedium2–10%High> 10%Illustrative grid · simulated data
Figure.Aircraft-reported NIC/NACp degradation is aggregated into hexagonal cells per time window; cells where a meaningful share of aircraft report degraded quality form a daily interference layer, always read alongside coverage.

Scroll sideways to see the full diagram.

Formula

Degraded share (cell, window)=aircraft reporting degraded quality ÷ all aircraft observed with quality fields

where
Degraded quality
For example NACp = 0 after previously reporting NACp > 7 in the same flight, or NIC below the compliance floor
Aircraft observed
Distinct addresses with at least one position and quality report in the cell and window
Cell
A hexagonal grid cell (for example an H3 cell), chosen so typical cells contain enough aircraft per day

Figuet and colleagues used OpenSky data to study Eastern Europe from February to August 2022. To avoid flagging aircraft that never report good accuracy (for example aircraft without GNSS receivers), they labelled a flight as affected only if it reported NACp = 0 for more than 60 seconds cumulatively and NACp above 7 for more than 60 seconds11. On 5 June 2022, more than 1,325 aircraft in their study area were affected, about 60% of the traffic, and affected flights spent on average less than 11 minutes with NACp at 0, though some were affected for over an hour11. They also found that low-flying aircraft were less affected than those at higher altitudes, consistent with line-of-sight propagation11.

Share of aircraft with degraded NACp in one cell cluster, by hour (UTC)
  • Degraded share
  • 28-day baseline
Figure. Illustrative data: simulated hourly values for a fictional region, showing the shape of a recurring interference episode against a near-zero baseline. Not real measurements.

The method has well-documented limits, and they should be printed on every map. Aircraft with tightly integrated GNSS and inertial navigation may report degradation late, distorting both the area and the duration of an event; flights already at NACp 0 when they enter an area cannot be detected; and coverage over water or in conflict areas may be thin or absent11. Localizing the source of interference from aircraft reports is an active research area with significant assumptions (one source, static, unobstructed propagation, adequate receiver coverage)12. We recommend that civil teams treat interference maps as indicators of where aircraft experienced degraded navigation, and leave source attribution to spectrum authorities and official reporting channels.

The step-by-step method, including thresholds, minimum-sample rules and SQL, is in the guide Detect GNSS interference from aircraft data, and a ready-made model is available as the GNSS interference monitor template.

§07Fusing tracks with weather, NOTAMs and reference data

A track on its own answers "where". Decision support needs "why" and "so what". Data fusion means joining independent sources on shared keys (time, place, identity) so that each corroborates or qualifies the others. For airspace awareness, five context layers do most of the work.

LayerJoin keyQuestions it answers
Weather observations and forecasts (METAR, TAF, SIGMET)Aerodrome / area and timeIs the holding pattern weather-driven? Is a diversion explained by conditions at destination?
NOTAMs and temporary restrictionsArea polygon, altitude band, validity windowIs this geofence active now? Is a GNSS outage already announced for this area?
Aerodromes and airspace structureGeometryIs the aircraft on approach, in a published hold, or somewhere unusual?
Receiver coverageCell, altitude band, hourIs a track gap explained by coverage or is it unexpected?
Aircraft type referenceAddress or registration where lawfulIs the climb profile plausible for this type?
Context layers for an open-data air picture.

Two fusion patterns are especially valuable. Interference corroboration: when an interference cell appears, check whether an official notice already covers it. The EASA–IATA plan calls for standardized NOTAM Q-codes for GNSS interference and for timely sharing of interference event data, including between civil and military authorities10. A cell that matches a published notice is confirmation; a cell that does not is a candidate for reporting through the proper channel. Emergency context: when a 7700 appears, automatically attach the latest weather at nearby aerodromes, any active restrictions, and the aircraft's altitude profile for the last 15 minutes. The analyst should not have to open five tabs.

In Kimo, each layer is a source in the same semantic model, so the join logic is written once and reused by the map, by alerts and by Ask Kimo. Combining aircraft data with maritime AIS works the same way, and the dark vessels article describes the gap-detection approach we reuse for tracks.

Connectors typically used in an open-data airspace workspace: ADS-B and OpenSky feeds, OpenStreetMap reference geometry, AIS for maritime fusion, Kafka for receiver streams, and Kimo Bridge to keep data on your own servers.

§08Designing alerts analysts will not mute

Airspace data produces an endless supply of "interesting" events: every go-around, every hold, every reception glitch. An alerting layer that surfaces all of them will be muted within a week. The aim is the opposite: a small number of alerts, each of which an analyst would agree deserved interruption. We use five design rules.

  1. Step 1:

    Alert on outcomes, enrich with causes

    Page on the event a human must act on (a persistent 7700, a cell crossing an interference threshold, a track entering an active restricted area). Attach supporting signals as context instead of alerting on each separately.

  2. Step 2:

    Debounce everything

    Require persistence across messages, receivers and time. The AIM documents that emergency codes can be selected momentarily by accident7; a single-frame squawk should never page anyone.

  3. Step 3:

    Normalize by coverage and baseline

    Compare against the same cell, hour and day-of-week baseline and only evaluate where coverage is adequate. "More events" in a cell that gained a receiver is not news.

  4. Step 4:

    Group and suppress

    Group alerts by incident (one aircraft, one cell cluster) and suppress repeats within a window. An interference episode is one alert that updates, not two hundred.

  5. Step 5:

    Measure precision and own each rule

    Every rule has an owner, a written purpose and a monthly review of how many alerts were useful. Retire rules that are not.

Weekly alerts reaching analysts, before and after tuning
  • Raw rule matches
  • Alerts delivered
Figure. Illustrative data: simulated weekly alert counts for a fictional regional team after introducing debouncing, coverage gating and incident grouping. Not customer data.

Kimo expresses alert rules as versioned YAML next to the data model, so a threshold change is reviewed like code and visible in the activity log. Examples for emergency squawks, loitering, altitude anomalies, geofences and interference cells are in the alerting guide and the alerts documentation.

§09Privacy, licensing and the law

Signals being receivable does not make every use of them appropriate. Three bodies of rules apply to most open-data airspace programs: aviation privacy programs, data-protection law, and the license terms of the data you consume.

Aviation privacy programs

The FAA runs two complementary programs. LADD (Limiting Aircraft Data Displayed) blocks aircraft data provided through the FAA's own data feed; it does not affect what the aircraft broadcasts13. The Privacy ICAO Address (PIA) program lets eligible owners request an alternate, temporary ICAO address that is not assigned to them in the civil aircraft registry, specifically to limit how easily an aircraft can be identified by inexpensive receivers13. A responsible pipeline honors both: it does not attempt to re-identify PIA addresses, and it applies LADD-style suppression in any public-facing output.

Data protection

Under the GDPR, personal data is "any information relating to an identified or identifiable natural person"14. A flight track of a privately owned aircraft can relate to an identifiable person, directly or by combination with registry data. Where GDPR applies, the core principles bite: data must be collected for "specified, explicit and legitimate purposes", be "limited to what is necessary", and be kept in identifiable form "no longer than is necessary"14. Practically: define the purpose of each dataset (for example "regional GNSS interference monitoring"), aggregate where individual tracks are not needed (interference maps work on cells, not aircraft), and set retention per table. This is general information, not legal advice; involve your data-protection officer.

Data licensing

Open does not mean unlicensed. The OpenSky Network, for instance, grants access for non-profit research and education; any use by a for-profit or commercial entity, including government and military contractors, requires a written license, and operational use of its REST API, even internal, requires a prior written agreement15. Publications using its data must cite the founding paper15. Kimo's OpenSky connector asks you to confirm your license tier at setup, and we recommend recording the license basis for every source in the data catalog.

QuestionGood practice
Do we need individual tracks for this purpose?If not, aggregate to cells and time windows at ingestion
Could an output identify a private person?Suppress LADD/PIA aircraft and general aviation detail in shared views
How long do we keep raw state vectors?Set a short default (for example 30–90 days) and keep aggregates longer
Who can see restricted alerts (e.g. 7500)?Limit to a named group; log every view
Is our use covered by the source license?Record license basis per source; renew before operational use
Privacy and licensing checklist for open aviation data. Retention values are illustrative defaults, not legal requirements.

§10Ethics and the limits of open data

Open aviation data sits squarely in the OSINT tradition: information anyone can lawfully collect, made powerful by aggregation. Aggregation is also where the ethical risk lives. We think four commitments separate responsible programs from irresponsible ones.

  1. Civil purpose. Use the data for safety, research, crisis response, environmental analysis and verification. Do not use it to target, follow or harass people or to locate specific military assets.
  2. Never the sole basis for a decision. Open data is incomplete (coverage), unauthenticated (protocol) and sometimes wrong (equipment). It should prompt questions to authoritative sources, not replace them. Interference indications go to official reporting channels; emergencies are handled by ATC.
  3. Honest uncertainty. Every view shows coverage, source and quality. Every chart that is not measured says so. Every alert explains which rule fired and why.
  4. Proportionate retention and access. Keep the least detail for the shortest time, and restrict sensitive alert types to people who need them.
>ADS-B is still in the evaluation phase, however, and data provided by the system is not certified and therefore not yet used for air traffic management.
— Schäfer et al., Bringing up OpenSky (2014), describing ADS-B at the time

Much has changed since 2014: equipage mandates such as the US rule have been in force since 20202, and quality floors are now regulated3. What has not changed is the distinction between certified surveillance, operated with redundancy and safety assurance by air navigation service providers, and an open-data pipeline built from volunteer receivers. The two can inform each other; they are not interchangeable.

§11A reference architecture in Kimo

The architecture below is how we deploy Kimo Defense Intelligence for civil airspace programs. It is deliberately boring: a small number of models with clear grain, reused everywhere.

LayerKimo objectGrainNotes
IngestConnector: ADS-B feed, OpenSky, own receivers via KafkaMessage or state vectorKeep raw for a short window; see the ingestion guide
NormalizeModel: state_vectorsAddress × timestampUnits in SI, quality fields carried, position source kept
SegmentModel: flightsAddress × flight segmentVersioned segmentation rule; gap threshold documented
CoverageModel: coverage_cellsCell × altitude band × hourComputed from own receptions
QualityModel: nav_quality_cellsCell × windowDegraded share with minimum-sample gating
ContextModels: weather, notices, aerodromes, airspaceVariesJoined on time and geometry
DecideAlert rules (YAML), Airspace map, Ask KimoIncidentDebounced, grouped, owned
Reference model layout for an open-data airspace workspace in Kimo.

Data residency is often the deciding constraint for civil-protection and research teams. With Kimo Bridge, the bridge runs on your own server next to your receiver database and opens an outbound-only, mutually authenticated tunnel; Kimo queries through it and nothing is stored on Kimo's side unless you enable short-lived caches. Teams that need fully disconnected operation run Kimo on-premise, as described in Air-gapped by design. Either way, the same models and rules apply, and the Airspace watch template provides a starting workspace with simulated data so you can evaluate the design before connecting anything real.

Excerpt: the nav_quality_cells model (Kimo YAML)
yaml
model: nav_quality_cells
source: state_vectors
grain: [h3_cell, window_start]
window: 1h
filters:
  - position_source = 'adsb'
  - nacp is not null
measures:
  aircraft_observed: count_distinct(icao24)
  aircraft_degraded: count_distinct(icao24) where degraded_flag
  degraded_share: aircraft_degraded / nullif(aircraft_observed, 0)
gating:
  min_aircraft_observed: 8
  require_coverage: true
retention: 400d   # aggregates only; raw state vectors expire after 30d

§12A maturity model for open-data airspace awareness

Teams rarely build all of this at once. The maturity model below is a way to sequence the work and to be honest about what a given stage can support.

StageCapabilityWhat it can supportWhat it cannot
1. PictureLive map from one feed, no quality fieldsCuriosity, demosAny conclusion about absence or anomalies
2. Qualified picturePosition source, NIC/NACp, coverage layerSituational awareness with stated confidenceTrend claims across time
3. ModeledFlights, coverage cells, baselines, context joinsResearch, retrospective analysis, reportingReal-time alerting at scale
4. AlertingDebounced, grouped, owned rules with precision trackingDuty-officer attention routingAutonomous decisions
5. GovernedPurpose, retention, access and license controls; auditSustained, accountable programs and publicationReplacing certified surveillance
Five-stage maturity model for open-data airspace awareness.

Note that the last column never becomes empty. Even a fully governed program does not replace certified air traffic surveillance or official interference reporting; it makes a civil team better informed and faster to ask the right question of the right authority.

§13Methodology and limitations of this paper

This paper synthesizes primary regulatory text (14 CFR 91.225 and 91.227, the FAA Aeronautical Information Manual), safety authority publications (EASA's GNSS outage bulletin page and the EASA–IATA mitigation plan), the FAA's aviation privacy program pages, the GDPR, the OpenSky Network's founding paper and license terms, a EUROCONTROL-commissioned multilateration study, and peer-reviewed research on interference detection from ADS-B. All sources were accessed in October 2026 and are listed below. Where we state Kimo design recommendations, they reflect our engineering practice, not external findings.

  • Regulatory scope. Equipage rules cited are US rules; other regions differ. Check the rules where you operate.
  • Evolving guidance. EASA's bulletin has been revised several times; consult the current revision rather than any summary, including this one.
  • Research generalization. Interference studies cited cover specific regions and periods; thresholds that worked there may need adjustment elsewhere.
  • Illustrative figures. Charts labelled "Illustrative data" are simulated and should not be read as measurements.
  • Not legal advice. The privacy and licensing chapter is general information for planning.

§14Conclusion

Open aviation data has made something remarkable possible: a civil team can see most cooperative air traffic, recognize emergencies within seconds, and map where aircraft struggle to navigate, all without a radar. The craft lies in what surrounds the dots: coverage modeled as data, quality fields carried everywhere, alerts that respect an analyst's attention, and governance that respects the people behind the tracks. Build in that order and open data becomes a trustworthy instrument for safety and research. Skip it and it becomes a confident-looking map of things that may not be true.

If you want to see the patterns in this paper running end to end, open the simulated Airspace view, start from the Airspace watch template, or read the hands-on guides on ingesting ADS-B feeds, detecting GNSS interference and alerting rules.

Sources (15)

Every factual claim above cites a numbered source. We link primary documents wherever they exist.

Sources

15 references
  1. Bringing Up OpenSky: A Large-scale ADS-B Sensor Network for Research (opens in a new tab)
    Schäfer, Strohmeier, Lenders, Martinovic, Wilhelm — ACM/IEEE IPSN2014cs.ox.ac.uk

    Network origins, 11 sensors, 720,000 km², >30% of European commercial traffic; position twice per second; 1030/1090 MHz; non-GNSS positions; NAC often unknown; 10-minute flight segmentation.

  2. 14 CFR § 91.225 — ADS-B Out equipment and use (opens in a new tab)
    Cornell Law School Legal Information Institute (US Code of Federal Regulations)law.cornell.edu

    Mandate after January 1, 2020; Class A requires 1090 MHz equipment; transmit-at-all-times rule and authorized exceptions.

  3. 14 CFR § 91.227 — ADS-B Out equipment performance requirements (opens in a new tab)
    Cornell Law School Legal Information Institute (US Code of Federal Regulations)law.cornell.edu

    Definitions of NACp and NIC; NACp < 0.05 NM and NIC < 0.2 NM; NIC changes broadcast within 12 seconds.

  4. The 1090 Megahertz Riddle (2nd ed.) — ADS-B basics (opens in a new tab)
    Junzi Sun, TU Delft (mode-s.org)mode-s.org

    112-bit frame structure, 24-bit address (reprogrammable), DF17 vs DF18/TIS-B, broadcast rates.

  5. Wide Area Multilateration — Report on EATMP TRS 131/04 (opens in a new tab)
    NLR for EUROCONTROL2005eurocontrol.int

    TDOA principle; four antennas for 3D, three with known altitude; no airborne changes required.

  6. On the Security of the Automatic Dependent Surveillance-Broadcast Protocol (opens in a new tab)
    Strohmeier, Lenders, Martinovic — IEEE Communications Surveys & Tutorials (arXiv preprint)2015arxiv.org

    Inherent lack of security measures in ADS-B; countermeasures including multilateration.

  7. Aeronautical Information Manual, Chapter 4 Section 1 (4-1-20 Transponder and ADS-B Out Operation; 4-1-21 phraseology) (opens in a new tab)
    Federal Aviation Administrationfaa.gov

    Inadvertent selection of 7500/7600/7700 causes momentary false alarms; emergency series indicators; 7500 hijack; SQUAWK MAYDAY = 7700.

  8. Global Navigation Satellite System outages and alterations (SIB 2022-02R4) (opens in a new tab)
    European Union Aviation Safety Agency (EASA)2026easa.europa.eu

    Jamming vs spoofing definitions, affected regions, symptoms, ANSP and operator recommendations; fourth revision of the SIB on 3 July 2026.

  9. EASA and IATA publish comprehensive plan to mitigate GNSS interference (opens in a new tab)
    EASA press release2025easa.europa.eu

    220% increase in GPS signal-loss events 2021–2024 (IATA FDX data); standardized NOTAM Q-codes; civil-military sharing of RFI event data.

  10. GNSS Jamming and Its Effect on Air Traffic in Eastern Europe (opens in a new tab)
    Figuet, Waltert, Felux, Olive — Engineering Proceedings 28(1), 12 (OpenSky Symposium)2022digitalcollection.zhaw.ch

    NACp-based detection criteria (60 s at 0 and 60 s above 7); 1,325 aircraft / 60% of traffic on 5 June 2022; altitude effect; limitations.

  11. Locating GNSS Interference Sources using ADS-B with Non-linear Least Squares (opens in a new tab)
    Liu, Lo, Blanch, Chen, Walter — NAVIGATION: Journal of the Institute of Navigation 72(3)2025navi.ion.org

    NIC every 0.4–0.6 s vs NACp every 2.4–2.6 s; NIC as proxy for GNSS reception quality; localization assumptions and limits.

  12. ADS-B Privacy (Privacy ICAO Address and LADD) (opens in a new tab)
    Federal Aviation Administrationfaa.gov

    PIA issues an alternate temporary address not assigned to the owner in the registry; LADD blocks FAA feed data, not the broadcast.

  13. Regulation (EU) 2016/679 (General Data Protection Regulation), Articles 4 and 5 (opens in a new tab)
    EUR-Lex, Official Journal of the European Union2016eur-lex.europa.eu

    Definition of personal data; purpose limitation, data minimisation, storage limitation.

  14. General Terms of Use & Data License Agreement (opens in a new tab)
    OpenSky Networkopensky-network.org

    Non-profit research/education license; commercial and operational use require a written license or agreement; citation requirement.

External sources were accessed at the time of writing. Kimo product details, customers and figures in examples are illustrative unless a source is cited.

Frequently asked questions

Is open ADS-B data accurate enough for safety decisions?
It is accurate enough to direct attention and to support research, but not to be the sole basis for a safety decision. Positions are self-reported and unauthenticated, coverage has gaps, and some aircraft are legitimately not transmitting. Use it to prompt questions to authoritative sources such as ATC or the relevant authority.
What is the difference between ADS-B, Mode S and MLAT?
ADS-B is the aircraft broadcasting its own position and state. Mode S is the secondary surveillance system whose replies carry identity and altitude but no position. MLAT locates a transmitter from the time differences at which several receivers hear the same signal, independent of what the aircraft reports.
How do you detect GNSS interference from aircraft data?
Aggregate the navigation-quality fields (NIC, NACp) that aircraft broadcast into grid cells and time windows, and flag cells where a meaningful share of aircraft that normally report good quality suddenly report degraded quality. Gate by minimum sample size and coverage, and treat the result as an indicator, not attribution.
Can we use OpenSky data in a commercial product?
Not without a license. OpenSky’s terms grant access for non-profit research and education; commercial entities and any operational use of the REST API require a written license or agreement. Check the current terms and record your license basis.
Does GDPR apply to flight tracks?
It can. Tracks of aircraft linked to identifiable people may be personal data. Where GDPR applies, define a specific purpose, aggregate when individual tracks are not needed, minimize retention, and involve your data-protection officer.
Can Kimo keep aviation data on our own servers?
Yes. With Kimo Bridge, data stays on your server and Kimo queries it through an outbound-only tunnel; for disconnected environments Kimo can run fully on-premise.
Written by
Hugo Lefèvre
Aviation data analyst at Kimo · Published Oct 5, 2026
All whitepapers
Cite this report

Lefèvre, H. (2026). Airspace Awareness from Open Data. Kimo Research. https://getkimo.com/whitepapers/open-data-airspace-awareness

All resources
GuideAdvanced
Defense

Ingest ADS-B feeds into Kimo

Connect a receiver network or OpenSky, normalize state vectors, and model flights and tracks.

Hugo Lefèvre
12 min read
GuideIntermediate
Defense

Airspace alerting rules that analysts trust

Emergency squawks, loitering, unusual altitude profiles and geofences, tuned to avoid alert fatigue.

Jonas Becker
11 min read

Airspace awareness from open data.

Fuse ADS-B, AIS and OSINT feeds on your own infrastructure. The demo runs entirely on simulated data.