Software ยท Console

Downrange

A firing range for avionics cyber readiness

Bus-level attack classes fired at a live detection stack and scored honestly - including the ones nothing on the bus can see. The evidence a program office asks for, built as a working console.

Six domains, one honest console.

The real DOWNRANGE readout, recreated - summary, operator, readiness, threat intel, PNT/EW, and provenance. Every program, bench, and score here is fictional; the engine, the scoring, and the honesty are real. Scroll the panel - each view is a working screen.

SUMMARY
EXECUTIVE SUMMARY Multi-domain avionics-cyber detection, proven on a real pen-test range. Fire a full MIL-STD-1553B attack taxonomy at the detection engine, score intercepts live, and ground every claim in real captured telemetry. Six domains - summary, operator, readiness, threat intel, PNT/EW, and the provenance that keeps it honest. DETECTION · FULL DEFENSE~94%16 of 17 a defender should catch ATTACK TAXONOMY33techniques · isolated scoring FALSE ALARMS0across benign vignettes + real cruise REAL BENIGN TELEMETRY~1,000position reports · zero flags WHAT THE HARNESS COVERS 8 ATTACK FAMILIES Eavesdrop · Injection · MITM · DoS RF · PNT spoof · Fuzzing · Implant 33 validated techniques, 0 modeled 10 CONTROL OVERLAYS Built-Ins · Hardened Bounds · Cmd Policy MITRE ATT&CK ICS · Protocol · Timing every gain is a ruleset, not a code change 4 ALERT DIALECTS Elastic Common Schema · TAK CoT program alert format · SIEM stream detection computed once, serialized many ways THE HONEST FRAME The pen-test proves the bus IDS can catch bus attacks. The ground truth says adversaries mostly show up on the network. DOWNRANGE holds both at once - capability and proportion - because a program office needs the second to prioritize the first. NO PROPRIETARY INFORMATION HAS BEEN USED TO DEVELOP THIS APPLICATION · ALL DATA FICTIONAL
PICKETbuild 7 OPERATOR · LIVE FIRE CANARY PASS ATTACK CLASS · 33 TECHNIQUES All 33 Eavesdrop 2 MITM 8 DoS 8 RF 3 PNT spoof 3 Fuzzing 4 Implant 2 CONTROL OVERLAY · RULESETS Built-Ins Hardened Bnds Command Policy DETECTION~94% INTERCEPTS16 ESCAPES1 FIDELITY33·0 FULL DEFENSE BUS PICKET EGRESS ← escape reaches egress ALERT OUTPUT · ONE EVENT, MANY DIALECTS ECS TAK CoT program alert fmt { "event.category": "intrusion_detection", "event.kind": "alert", "rule.name": "MITM targeted-high (LRU)", "verdict": "CATCH", "bus": "1553B", "rt.pair": "RT-17→RT-17", "attack.technique": "T0855", "severity": "HIGH" }
READINESS What we catch, and where it actually matters. LAYERED DEFENSE · RULES, NOT CODE Built-in content rules ~75% + hardened operational bounds ~88% + tier-2 command policy · full defense ~94% The engine core stays fixed. Each layer is a ruleset you can read, audit, and version - so a program office can trace which rule caught which round, and why. catches the physically-impossible → plausible-but-wrong → valid-but-malicious GROUND TRUTH · WHERE DETECTIONS LAND Snort + Zeek · networkwhere adversaries actually surface, by volume ≈ 95% Sagan · logs a few % Avionics IDS · 1553/429the databus lane - the capability this range proves smallest slice Replayed against a real captured alert stream, detection is overwhelmingly network-tier. A sobering honesty check: harden the network and log layers first. capability says what CAN be caught · proportion says what to fund first
avionics IDS · 1553/429the databus lane - the capability this range proves48 Snort + Zeek · networkwhere adversaries actually surface, by volume~4,750 MOST-RECENT ALERTS · ALL THREE LANES AV-IDS RT-17→RT-17 1553-RT17-SA05T0855 · HIGH AV-IDS RT-20→RT-12 1553-RT20-SA03T0856 · HIGH NIDS 10.4.1.22 → 172.16.0.9Snort · phishing-site NIDS 10.4.1.51 → 8.8.8.8Zeek · suspicious-DNS NIDS 10.4.1.33 → 45.9.x.xSnort · NetSupport-RAT LOG UUT syslogSagan · auth-anomaly BUS ALERTS BY SEVERITY CRITICAL8 HIGH33 MEDIUM7 One detection stack, three lanes, one alert picture - the bus lane where the range proves capability, the network lane where the volume lands.
PNT / EW INTEGRITY Per-attack EGI - what each PNT attack does to the nav solution. STRATEGIC · GPS INTEGRITY MAP low 0-2%med 2-10%high >10% where/when: ADS-B integrity (NIC) derived, not raw RF PER-ATTACK EGI · RT-08 · 1553-EGI-POS GPS jamming PNT-CAUGHT figure-of-merit9 → 31 m nav-modeGPS-aided → INS-only position drift rate1.8 m/s (INS coast) detectorEGI FOM-jump + mode-flip bound time-to-detect1.2 s from onset OTHER PNT CASES · SAME EGI TELEMETRY GPS spoofingCAUGHT slow-pull position walk FOM stays green, butsolution diverges from INS detector: cross-check residual EGI manipulationCAUGHT in-line data-word edit onthe 1553 EGI position words breaks protocol conformance detector: content + timing RF-enabled entryESCAPE no on-bus signal untilthe payload acts - scored missed, undetectable on-bus the honest residual, on the board Strategic where/when on the left; tactical per-tail nav effect on the right - the console holds both, and never fakes a catch it can't see.
PROVENANCE Every claim carries its source. That is what keeps it honest. VALIDATED 33 attack techniques run againstreal or bench-accurate 1553 traffic no synthetic scoring shortcuts MODELED 0 nothing on the scorecard is aprojection or a hopeful estimate fidelity reads 33·0 REAL BENIGN TELEMETRY ~1,000 actual position reports from areal cruise + 6 benign vignettes zero false alarms across all of it EVERY VALUE ON EVERY SCREEN IS LABELED validated telemetry - measured from the bus monitor stream self-computed - derived by the engine, formula shown modeled - explicitly flagged, never mixed with the above escape / undetectable - shown, not hidden, when nothing on the bus can see it THE AUDIT CHAIN A hash-chained, append-only journal records every execute, arm, disarm, and refusal - verifiable offline. A test director doesn't take the scorecard on faith. They replay the ledger and get the same numbers.
01 / SUMMARY

Capability and proportion, at once

The headline read: multi-domain detection proven on a real pen-test range, grounded in real benign telemetry. Thirty-three attack techniques across eight families, ten control overlays, four alert dialects - and the honest framing that a program office needs before it spends a dollar.

~94% full defense · 0 false alarms · 33 validated / 0 modeled
02 / OPERATOR

Fire the taxonomy, watch it land

Scope the rounds by attack class, toggle the control overlays, and fire down the bus against the detection engine. Green intercepts stop at PICKET; red escapes run through to egress. Every caught round emits its alert record - ECS, TAK CoT, or a program format - from one canonical event.

live tracers · caught vs escaped · one event, many dialects
03 / READINESS

What we catch, and where it matters

Two truths side by side. Layered defense climbs from ~75% to ~94% as rule layers stack - every gain data, not code. Ground truth shows the network tier carries ~95% of real alert volume, the avionics bus the smallest slice. Capability says what can be caught; proportion says what to fund first.

~75% → ~88% → ~94% · network ≈ 95%
04 / THREAT INTEL

One stack, three lanes

The unit under test runs the same stack this range exercises - the avionics IDS on the 1553/429 bus, Snort and Zeek on the network, Sagan on logs. The fleet alert picture, severity-ranked, in one live feed.

critical 8 · high 33 · medium 7
05 / PNT / EW

What each attack does to the nav solution

The strategic where-and-when of GPS interference, and the tactical per-attack EGI: figure-of-merit jump, nav-mode fallback, drift rate, and time-to-detect - per case, per tail. The console shows the honest residual too: attacks with no on-bus signal, scored missed rather than faked.

GPS jam: FOM 9 → 31 m · GPS-aided → INS-only · caught 1.2 s
06 / PROVENANCE

Every claim carries its source

Thirty-three validated, zero modeled. Real benign telemetry, zero false alarms. Every value on every screen is labeled - validated, computed, or modeled - and a hash-chained, append-only audit journal lets a test director replay the ledger and get the same numbers. That is what keeps it honest.

fidelity 33·0 · audit chain verifiable offline

The adaptive loop: escapes become detections.

Every escape is a specification for the rule that would have caught it. DOWNRANGE turns that into a workflow - and points at real-time threat mitigation at the edge.

01
Escape detected
a round runs the bus to egress - logged with its exact signature
02
Auto-draft rule
the harness proposes a Python detection script targeting that signature
03
Validate in harness
eval-before-merge: the new rule must lift the score without new false alarms
04
Push to SIL
the adapted ruleset ships to the systems-integration lab, near-real-time
05
SDR + AI edge ROADMAP
an SDR front-end and edge compute close the loop to real-time threat mitigation

Avionics cyber requirements stopped being a paperwork exercise. The evidence a test director asks for isn't a scan report.

Cyber survivability language now sits in platform RFPs, and government test organizations expect bus-level evidence - what happens on the MIL-STD-1553 bus under attack, not what the enterprise scanner found - before a systems-integration-lab slot gets scheduled. Most companies pursuing that work show up with policy binders and network scan reports. Neither answers the question the test director is going to ask.

The evidence that moves a program forward looks different: named attack classes executed against the actual data bus, a detector whose scoring is independent of the product being scored, and an audit trail somebody else can verify. That is instrumentation, and it has to be engineered.

The bearing: Downrange is that instrumentation, end to end - attack cases, clean-room detection, control-overlay scoring, a hardware-arm interlock, a tamper-evident audit chain. It sits here so a company pursuing DoD platform work can see the standard of evidence before a program office asks for it.

Five capabilities. One console, honest by construction.

i.

The firing lane

Nineteen attack classes across the MIL-STD-1553 threat surface - bus injection, spoofed remote terminals, timing manipulation, PNT interference - executed as live rounds against the detection stack. Intercepts flare green. Escapes stay red, because a range that hides its misses isn't a range.

ii.

An honest detection engine

Eight clean-room analyzers - bus conformance, timing, command policy, content, PNT integrity, terminal fingerprinting among them - read the monitor stream and decide caught or missed from the traffic itself. Attacks that emit no on-bus signal score as “missed, undetectable on-bus,” never as a fake catch. That honesty is the product.

iii.

Control-overlay readiness

Bus-level test cases crossed with security-control overlays and recomputed into a per-overlay readiness score. Stack an overlay, watch the detection rate move - the readiness argument becomes arithmetic instead of adjectives.

iv.

Alerts in the receiver's dialect

One canonical event model with thin serializers outward: Elastic Common Schema for the SIEM, Cursor-on-Target for TAK operational pictures, program alert formats for the command side. Detection is computed once; the paperwork is a serializer.

v.

An armed-and-audited command path

No case fires at real hardware without a named, authenticated operator, a software arm scoped to the hazard tier, and a physical transmit-inhibit interlock that reads fail-safe to unarmed. Every execute, arm, disarm, and refusal lands in a hash-chained, append-only audit journal a test director can verify offline.

Five layers. Clean-room detection, sealed evidence.

The console is self-contained: inline assets, embedded data, no external requests, CSP-safe. The bench runs mock-first, so the full attack suite executes with zero hardware. Detection is standards-only - no vendor code, no signatures - and the audit journal is verifiable with no network and no vendor tooling.

Layer 1

The console

A self-contained single page: inline CSS and JS, embedded data, no build step, no external requests, CSP-safe. Tabbed views for summary, operator, readiness, threat intel, PNT/EW, and provenance, in a dark cockpit-MFD idiom. It renders with no server running - the model view is a working artifact, not a demo shell.

Layer 2

The bench

A Python 3.12 + FastAPI backend executes attack cases against a real or simulated MIL-STD-1553 / ARINC 429 bench. Built mock-first: the full suite runs with zero hardware, and COTS 1553 interface cards drop in behind a driver seam without touching case or UI code.

Layer 3

The scoring authority

Bus monitor words normalize into an ordered, seekable message stream; the analyzers fuse to a verdict; windowed scoring grades captured, escaped-unexpected, and escaped-by-design against a ground-truth inject ledger. A golden-corpus replay gate - baseline, verify, diff - blocks any engine change that moves the numbers unexplained.

Layer 4

The command path

An authenticated gateway checks the operator before a driver even resolves; real hardware additionally requires the physical transmit-inhibit arm signal. The audit journal behind it is standard-library only - hash-chained, crash-tolerant, verifiable with no network and no vendor tooling.

Layer 5

The outputs

One canonical detection event serialized to Elastic Common Schema, CoT/TAK, and downstream alert formats; readiness rolls up per control overlay. The audit journal stays a separate, sealed stream from the detection feed - evidence and telemetry never share a channel.

Three clarifications.

  • Not a vendor IDS. The detection engine is clean-room and standards-only - published MIL-STD-1553B analysis techniques, no vendor code, rules, or signatures - so the scoring authority stays independent of any product being scored. A range that grades its own homework proves nothing.
  • Not an accreditation. A range scorecard is the evidence you bring to a government test organization, not a replacement for its process. Today's numbers run against a simulated golden corpus; hardware-in-the-loop rates arrive when the physical bench and its interlock are wired.
  • Not anyone's program data. Every program name, bench tag, operator, flight, and score on these screens is fictional. The engineering underneath - the analyzers, the interlock, the audit chain - is real and running.

If you're pursuing platform work with a cyber-survivability requirement, the first move is seeing what the evidence looks like.

One conversation, one written summary, no commitment. The bearing comes first.

Schedule a call - 30 min
Melbourne, FL · Working nationwide