{"id":"https://openalex.org/W4211105048","doi":"https://doi.org/10.1109/access.2022.3150840","title":"GDL90fuzz: Fuzzing - GDL-90 Data Interface Specification Within Aviation Software and Avionics Devices\u2013A Cybersecurity Pentesting Perspective","display_name":"GDL90fuzz: Fuzzing - GDL-90 Data Interface Specification Within Aviation Software and Avionics Devices\u2013A Cybersecurity Pentesting Perspective","publication_year":2022,"publication_date":"2022-01-01","ids":{"openalex":"https://openalex.org/W4211105048","doi":"https://doi.org/10.1109/access.2022.3150840"},"language":"en","primary_location":{"id":"doi:10.1109/access.2022.3150840","is_oa":true,"landing_page_url":"https://doi.org/10.1109/access.2022.3150840","pdf_url":"https://ieeexplore.ieee.org/ielx7/6287639/9668973/09709804.pdf","source":{"id":"https://openalex.org/S2485537415","display_name":"IEEE Access","issn_l":"2169-3536","issn":["2169-3536"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Access","raw_type":"journal-article"},"type":"article","indexed_in":["crossref","doaj"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://ieeexplore.ieee.org/ielx7/6287639/9668973/09709804.pdf","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5036288913","display_name":"Hannu Turtiainen","orcid":"https://orcid.org/0000-0002-7631-620X"},"institutions":[],"countries":[],"is_corresponding":true,"raw_author_name":"Hannu Turtiainen","raw_affiliation_strings":["Faculty of Information Technology, University of Jyv&#x00E4;skyl&#x00E4;, Jyv&#x00E4;skyl&#x00E4;, Finland"],"affiliations":[{"raw_affiliation_string":"Faculty of Information Technology, University of Jyv&#x00E4;skyl&#x00E4;, Jyv&#x00E4;skyl&#x00E4;, Finland","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5060661495","display_name":"Andrei Costin","orcid":"https://orcid.org/0000-0002-2704-9715"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Andrei Costin","raw_affiliation_strings":["Faculty of Information Technology, University of Jyv&#x00E4;skyl&#x00E4;, Jyv&#x00E4;skyl&#x00E4;, Finland"],"affiliations":[{"raw_affiliation_string":"Faculty of Information Technology, University of Jyv&#x00E4;skyl&#x00E4;, Jyv&#x00E4;skyl&#x00E4;, Finland","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5045716964","display_name":"Syed Khandker","orcid":"https://orcid.org/0000-0001-7899-7339"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Syed Khandker","raw_affiliation_strings":["Faculty of Information Technology, University of Jyv&#x00E4;skyl&#x00E4;, Jyv&#x00E4;skyl&#x00E4;, Finland"],"affiliations":[{"raw_affiliation_string":"Faculty of Information Technology, University of Jyv&#x00E4;skyl&#x00E4;, Jyv&#x00E4;skyl&#x00E4;, Finland","institution_ids":[]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5036786418","display_name":"Timo H\u00e4m\u00e4l\u00e4inen","orcid":"https://orcid.org/0000-0002-4168-9102"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Timo Hamalainen","raw_affiliation_strings":["Faculty of Information Technology, University of Jyv&#x00E4;skyl&#x00E4;, Jyv&#x00E4;skyl&#x00E4;, Finland"],"affiliations":[{"raw_affiliation_string":"Faculty of Information Technology, University of Jyv&#x00E4;skyl&#x00E4;, Jyv&#x00E4;skyl&#x00E4;, Finland","institution_ids":[]}]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5036288913"],"corresponding_institution_ids":[],"apc_list":{"value":1850,"currency":"USD","value_usd":1850},"apc_paid":{"value":1850,"currency":"USD","value_usd":1850},"fwci":0.8284,"has_fulltext":true,"cited_by_count":10,"citation_normalized_percentile":{"value":0.70066355,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":91,"max":99},"biblio":{"volume":"10","issue":null,"first_page":"21554","last_page":"21562"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11005","display_name":"Radiation Effects in Electronics","score":0.9993000030517578,"subfield":{"id":"https://openalex.org/subfields/2208","display_name":"Electrical and Electronic Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11005","display_name":"Radiation Effects in Electronics","score":0.9993000030517578,"subfield":{"id":"https://openalex.org/subfields/2208","display_name":"Electrical and Electronic Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T13295","display_name":"Safety Systems Engineering in Autonomy","score":0.9983999729156494,"subfield":{"id":"https://openalex.org/subfields/2213","display_name":"Safety, Risk, Reliability and Quality"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10761","display_name":"Vehicular Ad Hoc Networks (VANETs)","score":0.9968000054359436,"subfield":{"id":"https://openalex.org/subfields/2208","display_name":"Electrical and Electronic Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/avionics","display_name":"Avionics","score":0.9140678644180298},{"id":"https://openalex.org/keywords/fuzz-testing","display_name":"Fuzz testing","score":0.8223631381988525},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.5908573269844055},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.528533399105072},{"id":"https://openalex.org/keywords/protocol","display_name":"Protocol (science)","score":0.5273963809013367},{"id":"https://openalex.org/keywords/embedded-system","display_name":"Embedded system","score":0.5103945136070251},{"id":"https://openalex.org/keywords/avionics-software","display_name":"Avionics software","score":0.47068458795547485},{"id":"https://openalex.org/keywords/denial-of-service-attack","display_name":"Denial-of-service attack","score":0.4682137966156006},{"id":"https://openalex.org/keywords/software","display_name":"Software","score":0.45878010988235474},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.35224008560180664},{"id":"https://openalex.org/keywords/engineering","display_name":"Engineering","score":0.29329001903533936},{"id":"https://openalex.org/keywords/software-development","display_name":"Software development","score":0.23453006148338318},{"id":"https://openalex.org/keywords/component-based-software-engineering","display_name":"Component-based software engineering","score":0.16466215252876282},{"id":"https://openalex.org/keywords/the-internet","display_name":"The Internet","score":0.10909542441368103}],"concepts":[{"id":"https://openalex.org/C15792166","wikidata":"https://www.wikidata.org/wiki/Q221329","display_name":"Avionics","level":2,"score":0.9140678644180298},{"id":"https://openalex.org/C111065885","wikidata":"https://www.wikidata.org/wiki/Q1189053","display_name":"Fuzz testing","level":3,"score":0.8223631381988525},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.5908573269844055},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.528533399105072},{"id":"https://openalex.org/C2780385302","wikidata":"https://www.wikidata.org/wiki/Q367158","display_name":"Protocol (science)","level":3,"score":0.5273963809013367},{"id":"https://openalex.org/C149635348","wikidata":"https://www.wikidata.org/wiki/Q193040","display_name":"Embedded system","level":1,"score":0.5103945136070251},{"id":"https://openalex.org/C109905503","wikidata":"https://www.wikidata.org/wiki/Q4828920","display_name":"Avionics software","level":5,"score":0.47068458795547485},{"id":"https://openalex.org/C38822068","wikidata":"https://www.wikidata.org/wiki/Q131406","display_name":"Denial-of-service attack","level":3,"score":0.4682137966156006},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.45878010988235474},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.35224008560180664},{"id":"https://openalex.org/C127413603","wikidata":"https://www.wikidata.org/wiki/Q11023","display_name":"Engineering","level":0,"score":0.29329001903533936},{"id":"https://openalex.org/C529173508","wikidata":"https://www.wikidata.org/wiki/Q638608","display_name":"Software development","level":3,"score":0.23453006148338318},{"id":"https://openalex.org/C174683762","wikidata":"https://www.wikidata.org/wiki/Q609588","display_name":"Component-based software engineering","level":4,"score":0.16466215252876282},{"id":"https://openalex.org/C110875604","wikidata":"https://www.wikidata.org/wiki/Q75","display_name":"The Internet","level":2,"score":0.10909542441368103},{"id":"https://openalex.org/C142724271","wikidata":"https://www.wikidata.org/wiki/Q7208","display_name":"Pathology","level":1,"score":0.0},{"id":"https://openalex.org/C71924100","wikidata":"https://www.wikidata.org/wiki/Q11190","display_name":"Medicine","level":0,"score":0.0},{"id":"https://openalex.org/C204787440","wikidata":"https://www.wikidata.org/wiki/Q188504","display_name":"Alternative medicine","level":2,"score":0.0},{"id":"https://openalex.org/C146978453","wikidata":"https://www.wikidata.org/wiki/Q3798668","display_name":"Aerospace engineering","level":1,"score":0.0}],"mesh":[],"locations_count":3,"locations":[{"id":"doi:10.1109/access.2022.3150840","is_oa":true,"landing_page_url":"https://doi.org/10.1109/access.2022.3150840","pdf_url":"https://ieeexplore.ieee.org/ielx7/6287639/9668973/09709804.pdf","source":{"id":"https://openalex.org/S2485537415","display_name":"IEEE Access","issn_l":"2169-3536","issn":["2169-3536"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Access","raw_type":"journal-article"},{"id":"pmh:oai:jyx.jyu.fi:123456789/79799","is_oa":true,"landing_page_url":"http://urn.fi/URN:NBN:fi:jyu-202202161529","pdf_url":null,"source":{"id":"https://openalex.org/S4306400563","display_name":"Jyv\u00e4skyl\u00e4 University Digital Archive (University of Jyv\u00e4skyl\u00e4)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I94722563","host_organization_name":"University of Jyv\u00e4skyl\u00e4","host_organization_lineage":["https://openalex.org/I94722563"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"acceptedVersion","is_accepted":true,"is_published":false,"raw_source_name":null,"raw_type":"A1"},{"id":"pmh:oai:doaj.org/article:7d0c8533435f444994a728704d67e3cf","is_oa":true,"landing_page_url":"https://doaj.org/article/7d0c8533435f444994a728704d67e3cf","pdf_url":null,"source":{"id":"https://openalex.org/S112646816","display_name":"SHILAP Revista de lepidopterolog\u00eda","issn_l":"0300-5267","issn":["0300-5267","2340-4078"],"is_oa":true,"is_in_doaj":true,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"IEEE Access, Vol 10, Pp 21554-21562 (2022)","raw_type":"article"}],"best_oa_location":{"id":"doi:10.1109/access.2022.3150840","is_oa":true,"landing_page_url":"https://doi.org/10.1109/access.2022.3150840","pdf_url":"https://ieeexplore.ieee.org/ielx7/6287639/9668973/09709804.pdf","source":{"id":"https://openalex.org/S2485537415","display_name":"IEEE Access","issn_l":"2169-3536","issn":["2169-3536"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Access","raw_type":"journal-article"},"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G2091270419","display_name":null,"funder_award_id":"research-infras-2016072533","funder_id":"https://openalex.org/F4320320300","funder_display_name":"European Commission"},{"id":"https://openalex.org/G4431648444","display_name":null,"funder_award_id":"00211119","funder_id":"https://openalex.org/F4320321726","funder_display_name":"Suomen Kulttuurirahasto"},{"id":"https://openalex.org/G4447653093","display_name":null,"funder_award_id":"Network","funder_id":"https://openalex.org/F4320320300","funder_display_name":"European Commission"},{"id":"https://openalex.org/G5849237866","display_name":"The SESAR Knowledge Transfer Network","funder_award_id":"783287","funder_id":"https://openalex.org/F4320320300","funder_display_name":"European Commission"},{"id":"https://openalex.org/G6977260880","display_name":"EFFECT OF NATURAL VIRAL RNA SEQUENCE VARIATION ON INFLUENZA VIRUS RNA FUNCTION","funder_award_id":"201607","funder_id":"https://openalex.org/F4320320300","funder_display_name":"European Commission"},{"id":"https://openalex.org/G8051717526","display_name":null,"funder_award_id":"Grant","funder_id":"https://openalex.org/F4320320300","funder_display_name":"European Commission"},{"id":"https://openalex.org/G8318064016","display_name":null,"funder_award_id":"Horizon","funder_id":"https://openalex.org/F4320320300","funder_display_name":"European Commission"},{"id":"https://openalex.org/G8826631963","display_name":null,"funder_award_id":"Horizon 2020 Program","funder_id":"https://openalex.org/F4320320300","funder_display_name":"European Commission"}],"funders":[{"id":"https://openalex.org/F4320320300","display_name":"European Commission","ror":"https://ror.org/00k4n6c32"},{"id":"https://openalex.org/F4320321726","display_name":"Suomen Kulttuurirahasto","ror":"https://ror.org/027xav248"},{"id":"https://openalex.org/F4320323168","display_name":"Jyv\u00e4skyl\u00e4n Yliopisto","ror":"https://ror.org/05n3dz165"}],"has_content":{"pdf":true,"grobid_xml":true},"content_urls":{"pdf":"https://content.openalex.org/works/W4211105048.pdf","grobid_xml":"https://content.openalex.org/works/W4211105048.grobid-xml"},"referenced_works_count":38,"referenced_works":["https://openalex.org/W1146707526","https://openalex.org/W1946476891","https://openalex.org/W2089255914","https://openalex.org/W2108785430","https://openalex.org/W2131018820","https://openalex.org/W2159099280","https://openalex.org/W2166778460","https://openalex.org/W2180970301","https://openalex.org/W2186548909","https://openalex.org/W2213950023","https://openalex.org/W2678414931","https://openalex.org/W2757104921","https://openalex.org/W2762217792","https://openalex.org/W2782780792","https://openalex.org/W2801872634","https://openalex.org/W2920974348","https://openalex.org/W2960121311","https://openalex.org/W2963350015","https://openalex.org/W2980672218","https://openalex.org/W3015291177","https://openalex.org/W3101988629","https://openalex.org/W3104664063","https://openalex.org/W3137949664","https://openalex.org/W3168821982","https://openalex.org/W4206565539","https://openalex.org/W4244269976","https://openalex.org/W6627472400","https://openalex.org/W6630729764","https://openalex.org/W6678042037","https://openalex.org/W6686936072","https://openalex.org/W6734136569","https://openalex.org/W6745908518","https://openalex.org/W6745987728","https://openalex.org/W6751903957","https://openalex.org/W6766830175","https://openalex.org/W6766958283","https://openalex.org/W6781000091","https://openalex.org/W7071269139"],"related_works":["https://openalex.org/W3186139453","https://openalex.org/W2111943161","https://openalex.org/W2017121998","https://openalex.org/W2378778713","https://openalex.org/W2137459428","https://openalex.org/W3125940229","https://openalex.org/W2167334428","https://openalex.org/W1544976691","https://openalex.org/W2133013354","https://openalex.org/W2380796682"],"abstract_inverted_index":{"As":[0],"the":[1,9,47,50,57,116,132,142,149,154,157,187,193,199,226,233],"core":[2,58],"technology":[3],"of":[4,49,180,198,225],"next-generation":[5],"air":[6],"transportation":[7],"systems,":[8],"Automatic":[10],"Dependent":[11],"Surveillance-Broadcast":[12],"(ADS-B)":[13],"is":[14,189],"becoming":[15],"very":[16],"popular.":[17],"However,":[18],"many":[19,183],"(if":[20],"not":[21],"most)":[22],"ADS-B":[23,124,168],"devices":[24],"and":[25,28,39,71,78,89,115,140,148,169,177,222,229,238,247,254],"implementations":[26],"support":[27],"rely":[29],"on":[30,56,94,102],"Garmin\u2019s":[31],"Datalink":[32],"90":[33],"(GDL-90)":[34],"protocol":[35,52,86],"for":[36,243],"data":[37],"exchange":[38],"encapsulation.":[40],"This":[41],"makes":[42],"it":[43],"essential":[44],"to":[45,69,145,192,208,252],"investigate":[46],"integrity":[48],"GDL-90":[51,85,117,150,162,230],"especially":[53],"against":[54],"attacks":[55,93],"subsystem":[59],"availability,":[60],"such":[61,74],"as":[62,75,160,219,257,259],"denial-of-service":[63],"(DoS),":[64],"which":[65],"pose":[66],"high":[67],"risks":[68],"safety-critical":[70],"mission-critical":[72],"systems":[73],"in":[76,156,182],"avionics":[77,112,125,171,204,244],"aerospace.":[79],"In":[80],"this":[81],"paper,":[82],"we":[83,106],"consider":[84],"fuzzing":[87,134,234],"options":[88],"demonstrate":[90],"practical":[91],"DoS":[92],"popular":[95],"electronic":[96],"flight":[97],"bag":[98],"(EFB)":[99],"software":[100,152,248],"operating":[101],"mobile":[103],"devices.":[104,126,172],"Then":[105],"present":[107],"our":[108,129,203],"own":[109],"specially":[110],"configured":[111],"pentesting":[113,205,241],"platform":[114,135,206],"protocol.":[118],"We":[119,127],"captured":[120],"legitimate":[121,161],"traffic":[122,163],"from":[123,167],"ran":[128],"samples":[130],"through":[131],"state-of-the-art":[133],"American":[136],"Fuzzy":[137],"Lop":[138],"(AFL)":[139],"fed":[141],"AFL\u2019s":[143],"output":[144],"EFB":[146,184,227],"apps":[147,228],"decoding":[151],"via":[153],"network":[155],"same":[158],"manner":[159],"would":[164],"be":[165,250],"sent":[166],"other":[170],"The":[173,215],"results":[174],"showed":[175],"worrying":[176],"critical":[178],"lack":[179],"security":[181,188],"applications":[185],"where":[186],"directly":[190],"related":[191],"aircraft\u2019s":[194],"safe":[195],"navigation.":[196],"Out":[197],"16":[200],"tested":[201],"configurations,":[202],"managed":[207],"crash":[209],"or":[210],"otherwise":[211],"impact":[212],"9":[213],"(56%).":[214],"observed":[216],"problems":[217],"manifested":[218],"crashes,":[220],"hangs,":[221],"abnormal":[223],"behaviors":[224],"decoders":[231],"during":[232],"test.":[235],"Our":[236],"developed":[237],"proposed":[239],"systematic":[240],"methodology":[242],"devices,":[245],"protocols,":[246],"can":[249],"used":[251],"discover":[253],"report":[255],"vulnerabilities":[256],"early":[258],"possible.":[260]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":1},{"year":2024,"cited_by_count":2},{"year":2023,"cited_by_count":3},{"year":2022,"cited_by_count":3}],"updated_date":"2026-03-27T05:58:40.876381","created_date":"2025-10-10T00:00:00"}
