Software · Console

Downrange

A firing range for avionics cyber readiness

Bus-level attack classes fired at a live detection stack and scored honestly — including the ones nothing on the bus can see. The evidence a program office asks for, built as a working console.

Views of the console.

Interface portraits. Every program name, bench tag, operator, and score is fictional — the engineering underneath is real.


AW Downrange FIRING LANE · MIL-STD-1553B 17/18 CAPTURED · 1 ESCAPED BY DESIGN ATTACK CLASSES INJECTION INJ-04 false RT status INJ-07 illegal command SPOOFING SPF-02 RT impersonation SPF-05 BC takeover TIMING TMG-02 minor-frame skew PNT PNT-01 GNSS spoof EXFIL EXF-03 passive tap LIVE LANE ATTACKER SPF-05 firing 1553 BUS monitor tap DETECTOR caught LAYERED DEFENSE · DETECTION RATE BY OVERLAY Baseline 71% + hardened bounds 87% + command policy 93% HONEST RESIDUAL EXF-03 passive tap emits no on-bus signal — scored missed, undetectable on-bus. A range that hides its misses proves nothing. The escape stays on the board. OPERATOR T. REYES · VANGUARD TEST WING ARM STATE SIMULATED BENCH · hardware inhibit engaged AUDIT hash-chained · 34 events this run · verified
Firing lane.   Named attack classes fired at the detection stack. Intercepts flare green; escapes stay red, including the one that is undetectable on the bus by design.

READINESS · CASES × OVERLAYS ATLASTRIDENTMERIDIAN Injection Spoofing Timing PNT integrity Exfil PER-OVERLAY READINESS Atlas baseline71% Trident hardened87% Meridian policy93% ALERT DIALECT ECS CoT/TAK same event, either serializer
Readiness matrix.   Bus test cases crossed with control overlays, recomputed per overlay. The readiness argument becomes arithmetic instead of adjectives.

PNT / EW WATCH GNSS INTERFERENCE · SKYHAWK MOA L1 nominal · L2 degraded · red denied BASELINE FLIGHT TRIDENT 21 FL350 · benign POSITION REPORTS 968 received INTEGRITY LOCKED · nominal EXERCISE SKYHAWK MOA · IRON COMPASS 26 Interference cells graded L1/L2/denied on a fictional grid.
PNT / EW watch.   GNSS-interference heatmap over a training range with a benign flight baseline — the picture a test director reads before a hardware run.

Illustrative interface portraits · All programs, benches, operators, and scores are fictional.

Avionics cyber requirements stopped being a paperwork exercise. The evidence a test director asks for isn't a scan report.

Cyber survivability language now sits in platform RFPs, and government test organizations expect bus-level evidence — what happens on the MIL-STD-1553 bus under attack, not what the enterprise scanner found — before a systems-integration-lab slot gets scheduled. Most companies pursuing that work show up with policy binders and network scan reports. Neither answers the question the test director is going to ask.

The evidence that moves a program forward looks different: named attack classes executed against the actual data bus, a detector whose scoring is independent of the product being scored, and an audit trail somebody else can verify. That is instrumentation, and it has to be engineered.

The bearing: Downrange is that instrumentation, end to end — attack cases, clean-room detection, control-overlay scoring, a hardware-arm interlock, a tamper-evident audit chain. It sits here so a company pursuing DoD platform work can see the standard of evidence before a program office asks for it.

Five capabilities. One console, honest by construction.

i.

The firing lane

Nineteen attack classes across the MIL-STD-1553 threat surface — bus injection, spoofed remote terminals, timing manipulation, PNT interference — executed as live rounds against the detection stack. Intercepts flare green. Escapes stay red, because a range that hides its misses isn't a range.

ii.

An honest detection engine

Eight clean-room analyzers — bus conformance, timing, command policy, content, PNT integrity, terminal fingerprinting among them — read the monitor stream and decide caught or missed from the traffic itself. Attacks that emit no on-bus signal score as “missed, undetectable on-bus,” never as a fake catch. That honesty is the product.

iii.

Control-overlay readiness

Bus-level test cases crossed with security-control overlays and recomputed into a per-overlay readiness score. Stack an overlay, watch the detection rate move — the readiness argument becomes arithmetic instead of adjectives.

iv.

Alerts in the receiver's dialect

One canonical event model with thin serializers outward: Elastic Common Schema for the SIEM, Cursor-on-Target for TAK operational pictures, program alert formats for the command side. Detection is computed once; the paperwork is a serializer.

v.

An armed-and-audited command path

No case fires at real hardware without a named, authenticated operator, a software arm scoped to the hazard tier, and a physical transmit-inhibit interlock that reads fail-safe to unarmed. Every execute, arm, disarm, and refusal lands in a hash-chained, append-only audit journal a test director can verify offline.

Five layers. Clean-room detection, sealed evidence.

The console is self-contained: inline assets, embedded data, no external requests, CSP-safe. The bench runs mock-first, so the full attack suite executes with zero hardware. Detection is standards-only — no vendor code, no signatures — and the audit journal is verifiable with no network and no vendor tooling.

Layer 1

The console

A self-contained single page: inline CSS and JS, embedded data, no build step, no external requests, CSP-safe. Tabbed views for summary, operator, readiness, threat intel, PNT/EW, and provenance, in a dark cockpit-MFD idiom. It renders with no server running — the model view is a working artifact, not a demo shell.

Layer 2

The bench

A Python 3.12 + FastAPI backend executes attack cases against a real or simulated MIL-STD-1553 / ARINC 429 bench. Built mock-first: the full suite runs with zero hardware, and COTS 1553 interface cards drop in behind a driver seam without touching case or UI code.

Layer 3

The scoring authority

Bus monitor words normalize into an ordered, seekable message stream; the analyzers fuse to a verdict; windowed scoring grades captured, escaped-unexpected, and escaped-by-design against a ground-truth inject ledger. A golden-corpus replay gate — baseline, verify, diff — blocks any engine change that moves the numbers unexplained.

Layer 4

The command path

An authenticated gateway checks the operator before a driver even resolves; real hardware additionally requires the physical transmit-inhibit arm signal. The audit journal behind it is standard-library only — hash-chained, crash-tolerant, verifiable with no network and no vendor tooling.

Layer 5

The outputs

One canonical detection event serialized to Elastic Common Schema, CoT/TAK, and downstream alert formats; readiness rolls up per control overlay. The audit journal stays a separate, sealed stream from the detection feed — evidence and telemetry never share a channel.

Three clarifications.

  • Not a vendor IDS. The detection engine is clean-room and standards-only — published MIL-STD-1553B analysis techniques, no vendor code, rules, or signatures — so the scoring authority stays independent of any product being scored. A range that grades its own homework proves nothing.
  • Not an accreditation. A range scorecard is the evidence you bring to a government test organization, not a replacement for its process. Today's numbers run against a simulated golden corpus; hardware-in-the-loop rates arrive when the physical bench and its interlock are wired.
  • Not anyone's program data. Every program name, bench tag, operator, flight, and score on these screens is fictional. The engineering underneath — the analyzers, the interlock, the audit chain — is real and running.

If you're pursuing platform work with a cyber-survivability requirement, the first move is seeing what the evidence looks like.

One conversation, one written summary, no commitment. The bearing comes first.

Schedule a call — 30 min
Melbourne, FL · Working nationwide