lagen.nu
ENISA Space Threat Landscape 2025

ENISA Space Threat Landscape 2025

Utgivare
Europeiska unionens cybersäkerhetsbyrå
Antagen
2025-03-26
Språk
engelska
Ämnesord
Cyber Threats
Källa
www.enisa.europa.eu
Endast på engelskaEuropeiska unionens cybersäkerhetsbyrå har inte publicerat någon svensk version av detta dokument. Texten nedan återges på engelska, så som den publicerats av Europeiska unionens cybersäkerhetsbyrå.

SPACE THREAT LANDSCAPE

MARCH 2025 0 SPACE THREAT LANDSCAPE

March 2025

ABOUT ENISA

The European Union Agency for Cybersecurity, ENISA, is the Union’s agency dedicated to achieving a high common level of cybersecurity across Europe. Established in 2004 and strengthened by the EU Cybersecurity Act, the European Union Agency for Cybersecurity contributes to EU cyber policy, enhances the trustworthiness of ICT products, services and processes with cybersecurity certification schemes, cooperates with Member States and EU bodies, and helps Europe prepare for the cyber challenges of tomorrow. Through knowledge sharing, capacity building and awareness raising, the Agency works together with its key stakeholders to strengthen trust in the connected economy, to boost resilience of the Union’s infrastructure, and, ultimately, to keep Europe’s society and citizens digitally secure. More information about ENISA and its work can be found here: www.enisa.europa.eu. CONTACT For contacting the authors please use market@enisa.europa.eu For media enquiries about this paper, please use press@enisa.europa.eu EDITORS Evangelos Rekleitis, ENISA Monika Adamczyk, ENISA ACKNOWLEDGEMENTS We would like to thank the ENISA Advisory Group and the National Liaison Officers network for their valuable feedback. We would also like to thank experts from the European Commission (DG CNECT) and the European Union Agency for the Space Programme (EUSPA), national authorities including the Belgian Institute for Postal Services and Telecommunications (BIPT, Belgium), Communications Regulation Commission (CRC, Bulgaria), National Agency for the Security of Information Systems (ANSSI, France), National Centre for Space Studies (CNES, France), Federal Office for Information Security (BSI, Germany), Ministry of Foreign Affairs and International Cooperation (Italy), National Cybersecurity Agency (ACN, Italy), Authority for Digital Infrastructure (Netherlands), Regulatory Authority for Electronic Communications and Postal Services (RATEL, Serbia), Ministry for Digital Transformation (Spain), private sector stakeholders including Thales and Rhea Cyber Security Services, and Expert Group Space of BSI Alliance for Cybersecurity (in particular: Aris Patronis, Christoph Möbius, Florian Göhler, Manuel Hoffmann, Max Roth, Sascha Fankhänel, Stefanie Grundner), and the ENISA colleagues: Nikolaos Tantouris and Dimitrios Papamartzivanos.

1

SPACE THREAT LANDSCAPE

March 2025

LEGAL NOTICE This publication represents the views and interpretations of ENISA, unless stated otherwise. It does not endorse a regulatory obligation of ENISA or of ENISA bodies pursuant to the Regulation (EU) No 2019/881. ENISA has the right to alter, update or remove the publication or any of its contents. It is intended for information purposes only and it must be accessible free of charge. All references to it or its use as a whole or partially must contain ENISA as its source. Third-party sources are quoted as appropriate. ENISA is not responsible or liable for the content of the external sources including external websites referenced in this publication. Neither ENISA nor any person acting on its behalf is responsible for the use that might be made of the information contained in this publication. ENISA maintains its intellectual property rights in relation to this publication. COPYRIGHT NOTICE © European Union Agency for Cybersecurity (ENISA), 2025 This publication is licenced under CC-BY 4.0 “Unless otherwise noted, the reuse of this document is authorised under the Creative Commons Attribution 4.0 International (CC BY 4.0) licence (https://creativecommons.org/licenses/by/4.0/). This means that reuse is allowed, provided that appropriate credit is given and any changes are indicated”. For any use or reproduction of photos or other material that is not under the ENISA copyright, permission must be sought directly from the copyright holders. Luxembourg: Publications Office of the European Union, 2025 Linguistic version Output format Catalogue Number ISBN DOI English PDF Web TP-01-25-007-EN-N 978-92-9204-696-5 10.2824/8841206

2

SPACE THREAT LANDSCAPE

March 2025

TABLE OF CONTENTS

1. INTRODUCTION 7 1.1 BACKGROUND AND CONTEXT 8 1.2 POLICIES & STANDARDS 10 1.3 SCOPE & OBJECTIVES 11 1.4 METHODOLOGY 12 1.5 TARGET AUDIENCE 13 1.6 STRUCTURE OF THE REPORT 13 2. COMMERCIAL SATELLITES LIFECYCLE MODEL 15 2.1. GENERIC LIFECYCLE MODEL AND ACTORS 16 3. ASSET TAXONOMIES 23 3.1. GROUND SEGMENT 25 3.2. SPACE SEGMENT 26 3.3. USER SEGMENT 27 3.4. HUMAN RESOURCES SEGMENT 28 4. SPACE THREATS 29 4.1. SPACE THREAT TRENDS 29 4.2. THREAT ACTORS 31 4.3. THREAT TAXONOMY METHODOLOGY 33 4.4. THREAT TAXONOMY 34 5. RISK ASSESSMENT 37 5.1. SCENARIO 1: COMMUNICATIONS PROTOCOL COMPROMISE VIA SOCIAL ENGINEERING 37 5.2. SCENARIO 2: EXPLOITING OBC/OBSW VULNERABILITIES VIA MALICIOUS CODE 40 5.3. SCENARIO 3: NETWORK INTRUSION DUE TO A LACK OF SECURITY PROTOCOLS AND MISCONFIGURATION 43

3

SPACE THREAT LANDSCAPE March 2025 6. CYBERSECURITY CONTROL FRAMEWORK 47 6.1. CONTROLS TO THREATS MAPPING 50 7. CONCLUSIONS AND RECOMMENDATIONS 69 ANNEX A - LIST OF ACRONYMS AND ABBREVIATIONS 73 ANNEX B – DETAILED ASSET TAXONOMY 75 ANNEX C – SPACE THREAT TAXONOMY 85 ANNEX D – CYBERSECURITY CONTROL FRAMEWORK 96

4

SPACE THREAT LANDSCAPE

March 2025

EXECUTIVE SUMMARY

This report underlines the growing importance of cybersecurity considerations for the space industry, with an emphasis on commercial satellites. Previous years have witnessed several notable cyber-attacks aimed at the space industry, including large-scale satellite systems, with consequences being not only visible, but also potentially harmful for societies at large. At the same time, the growing body of EU frameworks regulating network and information security as well as resilience of critical and important sectors, recognises the space sector among essential entities, thus subjecting it to strict cybersecurity requirements that will be applicable from January 2025. With this in mind, the primary objective of this report is to identify and assess the cybersecurity threat landscape for commercial satellites – exploring both existing and emerging challenges for the industry. This is achieved by focusing on cybersecurity aspects at each phase of the satellite lifecycle – development, deployment, operations, and decommissioning, and the stakeholders involved. The report defines a high-level reference architecture for commercial satellites presented in the form of a space assets taxonomy. The assets taxonomy is then matched against identified relevant threats and threat actors providing a space threat taxonomy, supplemented with possible risk scenarios and disruption models. Serving as a basic form of threat modelling, the scenarios, together with preceding sections, provide a baseline for designing a set of tailored cybersecurity controls derived from existing cybersecurity frameworks. The controls are aimed at providing guidance for strengthening resilience of commercial satellite operators. The report is aimed at a wide target audience – which includes representatives of the public/government sector and the space industry, technical and cybersecurity communities, as well as academia, standardisation bodies, civil society organisations, and the interested public. Among the key cybersecurity challenges faced by the commercial satellites industry, the report outlines: • Supply chain risks, with the space sector heavily dependent on complex global supply chains; • Use of third party Commercial Off-the-Shelf (COTS) components; • Legacy systems, due to the remote nature and location of space systems; • Limited visibility, again related to the remote nature of the space systems; • Weak configuration, primarily found in the lack of cryptographic technologies; • Human error, since space systems dependent on a high degree of human interaction in all phases of their lifecycle; and • The threat of sophisticated cyber-attacks, launched by skilled and capable threat actors To address these, some of the most notable recommended actions identified by the report include: • Implementing security by default and by design principles; • Analysis, testing, and hardening of COTS before and after introducing them into the production environment (operations); • Strengthened physical security of all ground-based assets, as well as space assets prior to their launch;

5

SPACE THREAT LANDSCAPE

March 2025

• Deployment of validated and tested cryptographic technologies measures into space systems; • Introduction of robust segmentation measures; • Regular patching and hardening of space systems; • Adopting a zero-trust approach; and • Adopting sound and appropriate cyber hygiene practices.

6

SPACE THREAT LANDSCAPE

March 2025

1. INTRODUCTION

The United Nations Office for outer Space Affairs (UNOOSA) Index of Objects Launched into Outer Space counts a total of 17,852 objects, out of which 11,331 are currently registered having an ‘in orbit’ status. As of 19 September 2024, the satellite tracking website “Orbiting Now” lists 10,786 active satellites in various Earth orbits. Taking a closer look into satellite operators shows that the commercial space sector is taking the lead of the overall space landscape, with private companies owning most of the active satellites (over 60% among the top 10 satellite operators). Such rates of commercial exploitation of space, coupled with an increasing number of private companies also launching and operating Space-as-a-Service business models, have made the application of satellites a standard enabling practice across a myriad of sectors and solutions. This includes phones and internet access, critical communications, satellite TV and radio broadcast, land and water resources monitoring, precision farming, remote sensing, management of remote infrastructure, and logistics package tracking, amongst others. Satellites have also been defined as central to achieving the United Nations’ Sustainable Development Goals (SDGs) at the global level , as well as the objectives of the EU’s green and digital transition . However, by becoming the backbone of some of the key modern economic activities, the new “space race” has also increased the potential for harmful effects of any loss of capability, no matter the cause, opening the door for new vulnerabilities in parallel. The use of off the shelf and open source hardware and software components, trends such as software-defined satellites, in-orbit reconfigurations, onboard intelligence, and quantum technologies are all making space assets and data increasingly susceptible to cyber-attacks. Considering recent forecasts of an average 2,800 satellite launches annually between 2023 and 2032 – the equivalent of 8 satellites per day - there is an urgent need to address the risks and threats faced by the space sector today, to ensure uninterrupted and effective communication in the future. And yet, despite general agreement that the space domain requires targeted attention, with the lack of analysis and control over space-based infrastructure recognised among key cybersecurity threats to emerge by 2030 , there is still a relative lack of detailed, sector-specific cybersecurity guidelines for commercial satellite operators. Apart from NASA’s Best Practice 8 9 Guide published in January 2024, the Security in space systems lifecycles standard published by the European Cooperation for Space Standardization (ECSS) in July 2024, and a number of technical standards and guidelines that can be leveraged to support resilience of different satellite components, processes, or lifecycle phases, satellite operators are generally governed

7

SPACE THREAT LANDSCAPE

March 2025

by national rules and regulations prescribed by the country of their establishment, despite their operations having a wider reach and, often, a global impact. To this end, the aim of this report is to assess the cybersecurity threat landscape for the commercial satellite industry and to provide recommendations for effective and practical cybersecurity controls and mitigation strategies, considering the specific needs of commercial satellite operators. 1.1 BACKGROUND AND CONTEXT Cyber-attacks on satellites can be executed from the ground and the attackers do not necessarily need to be spacefaring nations. Real-life events have shown that even large-scale systems are susceptible to hostile takeovers, with the 2022 Viasat satellite hack serving as a notable example, shutting down tens of thousands of modems across Europe and disrupting not only economic activities of several European countries but also lifeline functions such as emergency services. In 2022, researchers identified several vulnerabilities in commercial 11,12 13 satellite infrastructure, enabling access to terminals as well as blind signal identification . The need to better understand the threats and vulnerabilities of satellite systems has led to a decision by the U.S. government to allow a group of hackers to attack a satellite deployed in orbit, during the 2023 August DEF CON conference , to identify further resilience measures that can be introduced. In the domain of space policy and satellite operations research, a number of publications have illustrated the severe consequences that can arise from targeted cyber attacks on critical space assets. They are further exacerbated with the recognised dual or multi-use of satellite infrastructure, whereby commercial technology intended for civilian use can nevertheless be 17,18 weaponised in support of geopolitical goals. Finally, research into the potential consequences of successful cyberattacks on commercial satellites also suggests the potential of cascading effects including: 1. Physical: Potential misalignment of satellite orbits, increasing the risk of collision with other space objects and exacerbating the challenges of space debris mitigation. The implications of a collision cascade in space are significant, potentially rendering orbits inaccessible and jeopardising the usability of entire regions of space. 2. Economic: A successful cyber intrusion resulting in a disruption of satellite services could lead to immediate and significant financial losses for businesses relying on uninterrupted communications and data transmission. Loss of satellite service in the industries that heavily depend on satellite connectivity, such as transportation, logistics, and remote monitoring, could result in costly downtime, delays, and

8

SPACE THREAT LANDSCAPE

March 2025

inefficiencies, potentially leading to stock market shutdowns, air traffic halts, or supply chain disruption. 3. Societal/Human: Following a successful cyber incident against a space system, a trickle-down effect can result in panic, food shortages, plundering, and social unrest, depending on the extent and duration of impact. Disruptions to essential services dependent on space systems, such as commercial aviation, may generate loss of human life and catastrophic consequences. 4. Legal/Regulatory: The compromise of sensitive information transmitted via satellites can lead to breaches of customer data and trade secrets, eroding trust in satellitebased services in the long run. Such incidents may also have legal and regulatory repercussions, potentially leading to fines and reputational damage for satellite operators, businesses involved in satellite-dependent operations, as well as a cascading effect resulting in geopolitical tensions. As commercial satellites increasingly underpin vital global communications, navigation, and essential services, addressing the risks posed by malicious actors targeting these systems is of paramount importance. The above-mentioned cases show the need for developing dedicated reference materials to provide a baseline for better sectoral security and resilience of the commercial satellite sector. When considering security in the context of satellite technologies, one needs to be aware that there are many entry points for malicious actors. These are dispersed across the satellite’s lifecycle, which encompasses everything from an initial idea to project planning, development, transport, launch, operation, and final decommissioning. Each phase of the lifecycle includes a multitude of relevant assets and actors, many of which can be a potential source of vulnerabilities. It is therefore essential to secure satellite solutions and apply “security by design” and “security by default” concepts as prerequisites for attaining zero-trust principles. This implies ensuring that cybersecurity considerations are knitted into every phase of the lifecycle process, and assuming a level of security that is proportional to the value of the protected assets. To successfully achieve this, it is important to: • understand the satellite lifecycle model; • understand what needs to be secured (the assets that are subject to satellite specific threats and adversarial models); • manage threats in a multi-party ecosystem in a comprehensive way by using interoperable models and taxonomies; and • implement relevant cybersecurity controls based on risk models to ensure strengthened security of satellite infrastructure. The introduction of minimum industry standards, based on “security by design” and “security by default” would also contribute to make cybersecurity attainable under the same or similar market conditions.

9

SPACE THREAT LANDSCAPE

March 2025

1.2 POLICIES & STANDARDS This subsection provides a snapshot of relevant policies for this report, including current frameworks, policies, standards, and guidelines that have a significant impact on commercial satellite solutions. At the EU level, the updated Directive on measures for a high common level of cybersecurity across the Union (NIS2 directive) now encompasses space as a sector of high criticality, comprising operators of ground-based infrastructure that support space-based services, as well as telecom operators. This provides an initial high-level set of obligations pertaining to cybersecurity that satellite operators need to abide by. These obligations may be further specified in the context of the national transposition of the NIS2 Directive in line with the minimum harmonisation approach. Moreover, under Article 21(5) of the NIS2 Directive, the Commission is empowered to adopt implementing acts to lay down the technical and the methodological requirements of the required measures. The Cyber Resilience Act (CRA), the first-ever EU-wide legislation addressing cybersecurity for products with digital elements, was published in the Official Journal on 20 November 2024 . Aiming to ensure that all products with digital elements placed on the EU market meet stringent cybersecurity standards throughout their lifecycle, the CRA is expected to have a significant impact on the development, operations and decommissioning of space systems.

Box 1. Additional EU policies and initiatives aimed at increasing the level of security of space systems, products, and communication

EU Cybersecurity Act establishing the European Cybersecurity Certification Framework, a harmonised approach to European cybersecurity certification schemes to attest that ICT products, services, and processes comply with specified security requirements, protecting the availability, authenticity, integrity and confidentiality of data and functions enabled, throughout their lifecycle. (Regulation EU 2019/881)

Council Resolution on Encryption calling for joined efforts at EU level in the technology industry to ensure continued implementation and use of strong encryption technology to protect against cyber threats. (13084/1/20)

EU Secure Connectivity Programme setting the goals for an EU satellite constellation (IRIS2) to provide EU Member States with guaranteed access to highly secure, low-latency and global connectivity services for the protection of critical infrastructure, surveillance and support for external action or crisis management, along with military applications. The security of these communications will be based on advanced encryption technologies, including quantum cryptography, and enable the provision of commercial infrastructure to provide high-speed broadband connectivity in the EU and in strategic areas further afield.

Recommendation on a Coordinated Implementation Roadmap for the Transition to Post-Quantum

Cryptography (PQC) encouraging a harmonised EU-wide approach for the adoption of PQC for public administrations and critical infrastructures. (C(2024) 2393 final) In terms of standardisation, the European Cooperation for Space Standardisation (ECSS) , a collaborative effort between the European Space Agency, national space agencies, and the European space industry associations plays a pivotal role. Facilitating management, engineering, product assurance, and sustainability in space projects and applications, ECSS focuses on developing standardised requirements to support European space activities. Further work on standardisation is provided by the Consultative Committee for Space Data Systems (CCSDS), currently the only body that is combining communications and security.

10

SPACE THREAT LANDSCAPE

March 2025

CCSDS’ Space Data Link Security (SDLS) protocol , at the data link layer of the Open Systems Intercommunication (OSI) stack, provides recommendations for ensuring confidentiality, integrity and authenticity of communication. Further developments in the standardisation domain are also expected from organisations such as the Institute of Electrical and Electronics Engineers (IEEE) which is currently working on a standard that will define cybersecurity controls for space systems. Looking at EU’s strategic partners, the United States’ Space Policy Directive 5 (SPD-5) , released in 2020, addresses the need for cybersecurity in space systems and directs federal agencies to collaborate with non-governmental space operators to establish cybersecurityinformed norms for space systems. SPD-5 has been a crucial milestone in establishing key cybersecurity principles for safeguarding space systems as it provides guidance on protecting space assets and supporting infrastructure from evolving cyber threats and mitigating the risk of harmful space debris caused by malicious cyber activities. Regarding standardisation, the National Institute of Standards and Technology (NIST) provides supporting materials for assessing and managing cybersecurity risk in the space domain with the Introduction to cybersecurity for commercial satellite operations specifically focusing on cybersecurity risk management in the commercial satellite industry. The US has a dedicated Space Information Sharing and Analysis Center (Space ISAC), launched in 2019 under the sponsorship of NASA, U.S. Space Force (formerly Air Force Space Command), and the National Reconnaissance Office. 1.3 SCOPE & OBJECTIVES The primary objective of this report is the identification and assessment of the cybersecurity threat landscape for the space sector, exploring both existing and emerging cybersecurity challenges in the satellite industry. By understanding potential cyber-related risks, threats, and vulnerabilities, the report aims to lay the groundwork for a trustworthy and uninterrupted deployment of commercial satellite systems and architecture. Focus is placed on cybersecurity threats and vulnerabilities across the satellite lifecycle and associated actors and assets identified as crucial components of satellite systems. Specific objectives include: • Definition of a generic commercial space system lifecycle model as well as identification and an analysis of satellite assets taxonomy, considering the stakeholders involved in respective lifecycle phases, interdependencies between the phases, groupings based on the lifecycle, as well as identifying their respective asset segments, i.e. ground-space-user; • Correlation of a list of threats, threat actors, and vulnerabilities, mapping them against a list of identified satellite assets. By examining potential threats, this report aims to provide insights into the vulnerabilities that may exist within existing and developing satellite projects; • Description of sample cyber-attack scenarios and failure models pertinent to various stages in the core commercial satellite lifecycle; and • Development of recommendations for effective and practical cybersecurity controls and mitigation strategies for the commercial space industry, helping them

11

SPACE THREAT LANDSCAPE

March 2025

protect their assets and ensure the continued safe and secure operation of space infrastructure. Overall, the Space Threat Landscape report endeavours to provide a holistic perspective on the cybersecurity challenges faced by commercial satellites. By identifying potential threats and vulnerabilities and providing a cybersecurity controls framework the report aims to equip stakeholders in the commercial satellite sector with the knowledge and insights needed to bolster the resilience and security of satellite systems in the face of evolving cyber threats. 1.4 METHODOLOGY The report is compiled based on publicly available, open-source resources collected through desk research. This includes frameworks, standards and guidance published by international organisations, national space agencies and standardisation bodies, as well as taxonomies, white papers and research published by the technical community and academia. Striving for general applicability, collected data has been dissected, cross-examined, and grouped based on contextual similarities. Certain aspects such as satellite lifecycle actors are presented in a generic format allowing further tailoring based on the specific purpose and design of a satellite. The approach employed for this report adheres to the methodology established by ENISA for its annual Threat Landscape assessments. Aligned with this methodology, the contents of the report were developed incrementally, starting with the definition of a reference lifecycle model and the identification of relevant infrastructure feeding into the asset taxonomy. This was followed by the identification of relevant threats and possible risk scenarios based on which relevant cybersecurity controls were defined. The lifecycle was developed comparing existing satellite lifecycle models employed by ESA, ECSS, BSI, NASA, JAXA and NIST. These were analysed to create an overview of existing approaches and identify similar and/or overlapping phases, providing a baseline for the generic lifecycle model for commercial satellites. The asset taxonomy is based on extensive literature survey of space infrastructures including frameworks published by national public and standardisation bodies, industry and technical communities and academic research. Identified assets were clustered and tagged to relevant segments based on common references and grouping found in the literature. The threat taxonomy is based on an examination of space and wider cybersecurity industry threat assessments addressing the space sector, industry reports, national space agencies’ and standardisation bodies’ guidelines and toolkits providing recommendations for defending against specific threats, academic research and analysis of known attacks on space infrastructure. Identified threats were clustered mirroring ENISA’s Threat Taxonomy. Linkages of threats to specific assets and their effects according to the CIA model (Confidentiality, Integrity, Availability) were made based on relations identified in the examined literature and the nature of the targeted assets. Threat actors are presented at a high-level and should be treated as hypothetical given the known challenges of clear attribution in the cyber domain. The proposed reference cybersecurity controls framework was derived based on a thorough review of existing cybersecurity frameworks, standards and guidelines published by relevant national and international authorities and standardisation bodies. Identified controls were then analysed to determine common objectives and patterns, overlaps, outliers, and gaps, enabling high-level, contextual control clustering based on relevance for the commercial satellites’ sector context. For the purpose of collecting relevant information and consulting on findings and proposed models and recommendations, ENISA has engaged experts from the European Commission (DG CNECT) and the European Union Agency for the Space Programme (EUSPA), national

12

SPACE THREAT LANDSCAPE

March 2025

authorities including the Belgian Institute for Postal Services and Telecommunications (BIPT, Belgium), Communications Regulation Commission (CRC, Bulgaria), National Agency for the Security of Information Systems (ANSSI, France), National Centre for Space Studies (CNES, France), Federal Office for Information Security (BSI, Germany), Ministry of Foreign Affairs and International Cooperation (Italy), National Cybersecurity Agency (ACN, Italy), Authority for Digital Infrastructure (Netherlands), Regulatory Authority for Electronic Communications and Postal Services (RATEL, Serbia), Ministry for Digital Transformation (Spain), private sector stakeholders including Thales and Rhea Cyber Security Services, and Expert Group Space of BSI Alliance for Cybersecurity (in particular: Aris Patronis, Christoph Möbius, Florian Göhler, Manuel Hoffmann, Max Roth, Sascha Fankhänel, Stefanie Grundner). Striving for broad applicability, the terminology employed within this report was built on the principles of ensuring holistic understanding, contextual relevance, knowledge integration, consistency, and easier updating and maintenance of the Space Threat Landscape report. 1.5 TARGET AUDIENCE The target audience for the Space Threat Landscape report includes various stakeholders concerned with the cybersecurity threats related to commercial satellites and space-based technologies. These stakeholders can be broadly categorized as follows: • Public/governmental sector (national and international level): Governing entities, space agencies, regulatory bodies, and authorities responsible for overseeing satellite operations, space policy, and national security. • Satellite industry: Companies and organizations involved in the satellite industry, including satellite operators, manufacturers, service providers, and other stakeholders within the satellite ecosystem, including the Satellite Industry and Space/Satellite Technical Community (e.g. Supply Chain and Logistics Providers), the User Community and Satellite Industry (e.g. Telecommunications Providers), and other relevant industry players. • Space and satellite technical community: Experts in space technology, satellite design, satellite operations, space mission planning, and related fields. • Cybersecurity community: Professionals and organizations with expertise in cybersecurity, particularly as it relates to space and satellite systems. • Academia and research community: Researchers, scholars, and educational institutions conducting studies and research in satellite technology and space-related cybersecurity. • Standardisation bodies: Organisations and committees involved in setting standards and best practices for space and satellite technology security. • Civil society and the general public: Individuals and organizations with an interest in space technology, satellite services, and the potential risks associated with spacebased systems. • User community: End users (consumers) of the services provided by space technology. 1.6 STRUCTURE OF THE REPORT Following this Introduction, the report is structured as follows: • Chapter 2 presents a generic lifecycle model for commercial satellite infrastructures, with relevant actors mapped to each of the lifecycle phases. The defined lifecycle phases are used as a baseline for subsequent definition of assets and relevant processes presented in succeeding chapters; • Chapter 3 details the assets in the satellite ecosystem based on the lifecycle stages defined in Chapter 2 and categorises them in 22 asset sub-domains, across the

13

SPACE THREAT LANDSCAPE

March 2025

ground, space, and user segments, with the addition of a human resources segment to account for the human dimension; • Chapter 4 introduces the threat taxonomy of satellite systems - where relevant threats are presented and mapped to corresponding assets that were introduced in Chapter 3; • Chapter 5 presents a risk assessment via specific risk scenarios and highlights cybersecurity-related challenges to satellite systems; • Chapter 6 outlines a proposed cybersecurity control framework tailored to the needs of commercial satellite operators, to address the threats identified in the threat taxonomy; • Chapter 7 concludes the report providing a summary of findings, highlighting cybersecurity challenges related to satellites systems, and proposing a set of high-level recommendations for strengthening resilience of commercial satellite operators.

14

SPACE THREAT LANDSCAPE

March 2025

2. COMMERCIAL SATELLITES LIFECYCLE MODEL

To meaningfully address the different aspects of the space domain, a systematic and structured approach should be applied. This includes considering all phases that a typical satellite system goes through during its lifecycle. This chapter presents a generic satellite lifecycle model, highlighting the components and entities (processes and actors) related to each of the lifecycle phases, as a foundation for the development of a satellite asset taxonomy, identification of potential threats and applicable risk scenarios. A study of lifecycle models for space projects employed by national space agencies Satellite lifecycle shows that, despite variations in the ways in which actions are grouped into phases or models are the terminology employed, at their core these lifecycles remain the same, regardless of the ownership or intended use of the satellite systems, and whether they are fundamentally commercial, military, or state-owned. These generally mirror a standard systems similar engineering process where the objectives and resources are first identified, followed by regardless of the a definition of requirements, ultimately leading to system design and development . intended use or Another common trait of models employed by ESA, NASA and JAXA is the application ownership of a of a phased approach where regular review cycles play a vital role in determining whether a given phase has met the necessary criteria to transition to the next one. For specific satellite. example, upon validation of design and manufacturing, the operation phase is launched by ensuring that all mission objectives are fulfilled. Once the goals of the mission are determined as complete or achieved, the system is decommissioned. Further analysis of additional lifecycle models employed by organisations such as BSI (i.e. IT- Grundschutz Profile for Space Infrastructures ) or NIST (i.e. Introduction to Cybersecurity for Commercial Satellite Operations ) shows that even the models that place stronger focus on cybersecurity aspects of satellite lifecycle operations nevertheless follow a similar phased logic. Figure 1 - Illustrates the phases of the satellite lifecycle models employed by prominent organisations governing the space sector and cybersecurity.

15

SPACE THREAT LANDSCAPE

March 2025

Figure 1: Phases of existing Satellite Lifecycle Models 2.1. GENERIC LIFECYCLE MODEL AND ACTORS This section presents a generic satellite lifecycle model developed on the basis of existing common practice, enabling the identification of processes and actors related to each lifecycle phase. The below lifecycle is developed based on the assessment of different frameworks discussed above, and by using NIST’s nomenclature as a generic skeleton.

16

SPACE THREAT LANDSCAPE

March 2025

Figure 2: Phases of a generic commercial Satellite Lifecycle Model Within the above lifecycle, various actors can be engaged across a range of activities, depending on the nature and mission purpose of a specific satellite. Based on the existing knowledge and the current demands for workforce in the aerospace industry, several broader types of actors, each relevant to a different phase of the commercial satellite lifecycle, are outlined in this report.

17

SPACE THREAT LANDSCAPE

March 2025

Actors include astronomers, atmospheric scientists, satellite operators, and engineers with a background ranging from aerospace engineering to cybersecurity, data, electronics, mechanics, and others. This group is essential for the initial design and development phases which form a foundation for successful development, operations, and retirement of a specific satellite. Other actors include test engineers who are responsible for ensuring that all the components are working as projected, as well as IT engineers that form the Satellite Operations Centre (SOC, also referred to as the Satellite Control Center - SCC) utilised for all sorts of in-orbit validations, custody management, mission execution, data and cybersecurity governance. While it is the SOC that primarily manage the satellite, during the retirement and disposal phases, aerospace engineers and scientists are reintroduced to manage its decommissioning. Finally, there are end users that benefit from satellites, including service consumers such as companies that utilise satellites to provide a specific service. The end users also include individual consumers that benefit from the services provided and/or enabled by commercial satellites, though in some cases they may be direct beneficiaries of a satellite solution as seen in the example of Starlink – a provider of wireless internet access . Apart from scientists and engineers who participate in the design, construction and operations of satellite systems and their supporting infrastructure, there is also a multitude of additional supporting actors who are irreplaceable from a process perspective. These actors can be clustered into two broad categories: specialists in fields necessary for production, including e.g. chemistry, material sciences and power engineering/energetics, and specialists in fields necessary for project management, such as human resources, finances, procurement, general management and administration. While the role and efforts of those specialists and their contribution to the overall mission is not to be underestimated, their involvement is not thoroughly examined in this report as it does not in any way differ from their functioning in other projects in different fields and. Therefore, they are considered at a general level, as part of the business-as-usual component of space missions and the overall satellite lifecycle. The following subsections provide a short description of each phase of the satellite lifecycle model and the individual actors involved. 2.1.1. Phase 1 – Design and Development This phase covers definition of requirements and assessments to ensure that the new project meets the mission goals and objectives. During this phase, the project team will set the ground for ideas, mission concepts, cost, system-level requirements, and technology needs, and will examine the mission’s overall feasibility. This leads to the creation of a mission concept review. Based on this concept, a list of system-level functional and security requirements is established and reviewed by technology experts with relevant expertise. The result of this process is the technical documentation, in which specific designs of satellite components are drafted. During design and development, robust software and hardware design processes should also incorporate security aspects, including security by design and by default principles. To this end, developers must ensure that implemented security features are proportional to the value of the assets and associated risks in case of compromise, fulfilling a security by default approach. Secure coding practices must be followed from the outset to minimise both vulnerabilities and cyber threats. Rigorous security testing, including penetration testing and vulnerability assessments, should be performed to identify and address potential weaknesses during these early phases of development. Manufacturers and companies also need to account for the long lifetime of some spacecrafts and build redundancy and flexibility into their designs to address evolving cyber threats over the vehicle's operational lifespan. Existing operational systems should also consider using compensating controls to achieve desired security outcomes if legacy technologies are

18

SPACE THREAT LANDSCAPE

March 2025

insufficient. Finally, supply chain management throughout the lifecycle should be assessed and governed utilising compliance forms and vendor vetting for cybersecurity standards employed prior to selecting specific vendors, who will provide satellite system components and services. Actors The design and development of a satellite requires a vast amount of knowledge, both theoretical and practical from differing scientific fields. Gathering, analysis and interpretation of such knowledge may involve astronomers, concerned with observation and analysis of processes and celestial bodies in the universe, physicists concerned with research of natural laws relevant for the design and development of satellites, atmospheric scientists, concerned with analysis of atmospheric phenomena and their relevance to the process and other various research and/or scientist profiles concerned with specific research tasks relevant to the process. Further, the design and development processes typically involve engineers from several differing fields. These include aerospace engineers, concerned with the overall development of the satellite; cybersecurity engineers, concerned with the security of a satellite’s IT components; data engineers / scientists, concerned with the collection, processing and analysis and interpretation of any data relevant to the development process; electronics engineers, concerned with the development of electronic features and equipment; software engineers, concerned with the development of software needed for the functioning of a satellite; manufacturing engineers, concerned with the production of specific satellite components; mechanical engineers, concerned with the specific mechanical devices and features; propulsion engineers, concerned with the design of satellite propulsion systems; and test engineers, concerned with planning and conducting of testing of satellites or their components. The design of a specific satellite may concern many differing aspects of engineering, IT, data science and other fields, depending on its defined mission. 2.1.2. Phase 2 - Assembly The assembly phase involves the procurement and integration of space assets/components and integrating them to enable the spacecraft to perform its missions. Apart from the assets that are relevant to the spacecraft itself, this phase also applies to the assets that are needed to support satellite operations/control. Hence, the successful review of the preliminary design leads to the finalisation of the detailed design of the system, including the production of hardware and code software guaranteeing that it can meet the requirements. Once the critical design review is approved, hardware procurement and software coding are initiated. Cybersecurity of the supply chain is one critical aspect in this phase. The procurement of spacecraft and ground/user components, from around the world demands careful validation of performance and cybersecurity functionality through tests and scheduled compliance audits. The hardware, firmware and software supply chain play a critical role in ensuring cybersecurity. While hardware modifications become limited once the spacecraft is launched, software modifications can often be conducted from the ground. Hence, addressing supply chain risks involves understanding supplier security and privacy policies, communicating requirements to suppliers, and engaging trusted vendors for all aspects of assembly. Organisations should establish secure communication channels with suppliers and ensure that components are not tampered with during transportation and assembly, as well as during mission execution (in the context of the software utilised). Continuous monitoring of the supply chain helps detect potential malicious activities. To ensure operational continuity in case of supply chain disruptions, organisations should consider supplier diversification, that is, maintaining a multisupplier strategy.

19

SPACE THREAT LANDSCAPE

March 2025

Actors The manufacturing of a satellite requires the physical production of satellite components by manufacturing technicians. The act of assembly itself requires the engagement of various technical personnel, including mechanical, aerospace and electronic technicians tasked with assembly of devices and components, specific to their specialisation. These technicians are also key for the provision of feedback to various engineers and other actors relevant to the design and development of satellites, for the optimisation and improvement of the satellite design. Based on the specific nature of individual satellites, further actors might be involved in the satellite’s assembly, such as laser technicians, avionics technicians, robotics technicians and other actors. 2.1.3. Phase 3 – Pre-launch Following the assembly phase, the pre-launch phase involves testing the satellite's functionality and establishing connectivity with ground control systems. At this point, focus is on the highlevel integration of the satellite with the launch vehicle, the launch infrastructure, and the satellite operations centre. The testing of this integration and the functionalities of all the above mentioned is also conducted, mainly on the level of different elements of the system (hardware, software, and human). This phase is also known for system integration, validation, and verification (IVV), and some industry players refer to it as such. Regardless, this phase also entails the preparation of the system for deployment and for performing the launch of the system itself followed by obtaining authorisation for it to be used/deployed. This phase is crucial for ensuring cybersecurity in satellite health and status monitoring systems. Operators must be vigilant about connectivity and access during pre-launch and control physical access to the vehicle during transit and storage at the launch facility. Cybersecurity is essential during this phase to ensure the integrity and confidentiality of the test environment and telemetry data. Operators should also validate the RF links and control access to critical satellite health and status monitoring systems. Actors Before the satellite is launched, its capabilities must be tested to assure that it operates according to its design. This task is usually delegated to test technicians, who test the various satellite avionic, electronic, and IT features. Their activities are managed by and reported to a launch authority, assisted by an operations safety manager, tasked with enforcing the security principles on the site of the launch. The atmospheric scientists and space weather scientists are tasked with assessing natural conditions at the time of the launch to ensure a safe launch. The route which the satellite and its carrier will follow to reach its destination in space must also be pre-planned. This is handled by flight dynamics engineers whose tasks are separated into two: knowing what the orbit injection characteristics delivered by the launcher will be and after injection (i.e.; separation of the spacecraft from the launcher), all the travel from the injection orbit to the final orbit (it lasts from a couple of days to half a year). Finally, the transportation of the satellite or its components is conducted by logistics and other support staff. 2.1.4. Phase 4 – Launch Moving the space system to its operational environment involves launch devices and installations, fuel operations, and safety systems. Due to the complexities and costs associated with the launch, this phase is outsourced. Additionally, the launch also includes Early Orbit Phase when the spacecraft is transferred from its injection point to the final orbit position. This process can last up to 6 months.

20

SPACE THREAT LANDSCAPE

March 2025

During the launch phase, cyber threats could target launch devices and installations, fuel operations, and safety systems. Cybersecurity measures should be in place to protect critical launch infrastructure and control systems. Additionally, in instances where the launch phase is outsourced, supply chain risks also must be considered to mitigate any breaches and malicious intrusion during this phase. Actors During the launch phase, two different organisations are usually involved. One is the launcher company, while the other one is the spacecraft manufacturer - both working hand in hand, with the launch being managed by a launch director (usually on the launcher company side). His tasks are the overall management of the process, its multiple components and personnel. An operations safety manager is concerned with the secure course of the launch. IT related aspects of the launch are conducted by the satellite operations centre operators (SOC operators), managed by the centre’s lead (SOC lead) and coordinated by the launch control lead, some of which can also be from the spacecraft manufacturer/operator side as these matters concern the satellite’ operability. The act of the launch is coordinated on-site by launch technicians, who ensure the correct course of its technical aspects. 2.1.5. Phase 5 – In-orbit Testing Once in orbit, satellites undergo post-launch checks to verify system integrity and operational status. This phase can be split into two steps: the first one following the injection into the transfer orbit (i.e. to make sure that the systems needed during the transfer work as expected), and the second, following the transfer before delivery to the customer. While the satellite has already established links with the ground command and control system, during this phase, the transfer of command and control from the development to the operating organisation occurs. In both cases, the customer/operator requires particularly heightened cybersecurity measures to address changes in custody and potential vulnerabilities. The in-orbit testing phase is critical for ensuring that the satellite systems have survived the launch and are operational, but also because it may offer opportunities for malicious actors to exploit vulnerabilities during the transfer of custody. Actors The operations of the satellite in orbit, including the activities immediately after it reaches its destination and enters a business-as-usual stage of operations, can be a fully automated process. However, even automated processes should be supervised by humans. Hence, the process is monitored by SOC operators, in case when an unexpected event occurs, such as a malfunction of a satellite or an unanticipated natural condition. In cases where the process is not automated, SOC operators conduct all the required tasks manually. Their activities are coordinated by the SOC leader. Depending on the nature of the satellite, the launch procedure, and the SOC, as well as other factors, a launch director and an operations safety manager can also be involved in this phase. 2.1.6. Phase 6 – Operations In the operations phase, the satellite conducts mission-specific functions, such as sensing, information processing, data acquisition, and communication. Operations are managed via the ground stations and centres that are critical for functioning and mission execution. Cybersecurity is crucial to maintaining the confidentiality, integrity, and availability of sensitive data and communications. Assets/components such as command and data handling, ground control systems, communication modules, command and control interfaces, onboard computers and software, data cryptographic mechanisms, satellite payloads, and firmware/software updates play a vital role in securing the satellite’s operations.

21

SPACE THREAT LANDSCAPE

March 2025

Actors As with the in-orbit testing, this phase includes automated solutions and/or SOC operators, coordinated by the SOC leader. Their tasks include management of operations of both the satellite payload and bus. The activities of SOC operators and the SOC leader can be supported by atmospheric scientists and space weather scientists, GIS analysts and other actors, depending on the nature of the satellite or in case of unexpected events occurring during its operations. Additionally, actors that typically work in the SOC include network and communication engineers, mission planners, payload operators, ground station operators, data analysts, logistics, support staff, and emergency response teams. Depending on the nature of a satellite, these actors can vary, but professionals working in the SOC collaborate closely to ensure the successful operations of a satellite throughout its mission. 2.1.7. Phase 7 – Decommissioning Decommissioning is a high-risk process involving the post-mission disposition of satellites and space structures. When a satellite is decommissioned, it is either removed from the orbit or left in space but sent further away from Earth. In case the satellite is removed from the orbit, the process includes re-entry or re-orbiting, followed by recovery and post landing analysis to understand the impact of the landing process on the satellite’s construction and materials. Proper handling of orbital debris and hazardous materials is essential, as are considerations for the secure handling and disposal of sensitive data, including intellectual property. Cybersecurity risks during decommissioning include data loss, corruption, unauthorised access and misuse by malicious actors, as well as potential physical threats to decommissioned systems. Improper decommissioning can also result in satellites becoming hijacked, broadcasting malicious signals, or posing a physical threat to other space assets through proximity operations or kinetic activity. Adherence to international standards, treaties, and domestic regulations is crucial. Actors The act of decommissioning is conducted by SOC operators, whose activities are coordinated by the SOC leader. They may be assisted by astronomers, atmospheric scientists, GIS analysts, and other actors, depending on the nature of the satellite to perform specific tasks in scope of decommissioning operations. The post-landing analysis is conducted by topical experts, such as material scientists, mechanical engineers, physicists and others (as needed) to accurately assess the impact of the landing process on the satellite.

22

SPACE THREAT LANDSCAPE

March 2025

3. ASSET TAXONOMIES

To ensure a streamlined and comprehensive approach, a ground-space-user classification for the satellite taxonomy is used and aligned with the lifecycle model described in the previous chapter. These three core segments are further broken down into categories, defined based on the specific process that related architecture supports, namely: • Production • Transportation • Launch • Satellite operations (from launch phase to decommissioning phase) • Mission execution • Consumer interfaces • Consumer endpoint devices The human dimension is addressed as a separate, horizontal ‘human resources’ segment to be considered across the entire asset taxonomy.

23

SPACE THREAT LANDSCAPE

March 2025

Figure 3: Asset Taxonomy Although primarily focusing on the critical assets that underpin the operational aspects of satellites throughout their lifecycle, the taxonomy also identifies third party ground services supporting satellite missions, such as launch services, transportation, or manufacturing systems. However, because the third-party services differ significantly and are physical and digital structures of their own, therefore they fall out of the remit of this report and are included only on high-level to ensure a holistic view of the primary and secondary infrastructure. This also enables subsequent identification of specific threats, such as third-party compromise and supply chain intrusion. A detailed assets taxonomy is provided in Annex B, further decomposing the segments and related categories outlined below into more specific asset subdomains and asset groups.

24

SPACE THREAT LANDSCAPE

March 2025

3.1. GROUND SEGMENT Figure 4: Detailed Asset Taxonomy – Ground segment This segment includes the terrestrial systems that facilitate communication, monitoring of satellite activities, and relaying of essential telemetry data, as well as brick and mortar facilities, manufacturing, logistics, and ultimately on-the-ground transportation. Categories defined in the Ground segment include: • Production includes assets needed for satellite development. It emphasises the importance of secure practices and concept known as “security by design and by default”, as this category also covers assets required during planning, design and development, cryptographic technologies, testing, and simulations, all of which are critical for ensuring confidentiality, integrity, and availability of the system throughout its lifecycle and mission execution. • Transportation includes assets that are being used for transportation of satellite components to the test and/or launch sites. • Launch includes assets associated with launch sites and launch control centres. Launch is, in the case of commercial satellites, commonly outsourced to third parties and only assets relevant to the mission itself are listed in the subsequent asset taxonomy.

25

SPACE THREAT LANDSCAPE

March 2025

• Satellite operations include assets related to the management, control, and monitoring of satellites throughout the mission lifecycle. This includes control centres and ground control stations, which provide a secure link to the satellite. Additionally, this includes Earth stations/Gateways (e.g. internet connectivity where the gateway serves as a hub for transmitting/receiving signal from the orbiting assets and transforms it to terrestrial connectivity). 3.2. SPACE SEGMENT Figure 5: Detailed Asset Taxonomy – Space segment • Satellite operations (BUS), also referred to as the ‘platform’, include all assets required to operate and maintain a satellite in orbit. The satellite bus operates independently from the payload, which is mission-specific. • Mission execution (satellite payload) includes assets needed to fulfil the mission. In some cases, payload systems rely on bus solutions to transmit and receive data and to communicate with ground stations and satellite/mission control centres. However, there is an increasing trend for keeping these two systems completely separated,

26

SPACE THREAT LANDSCAPE

March 2025

especially for missions where a satellite has multiple payloads which serve different consumers. 3.3. USER SEGMENT Figure 6: Detailed Asset Taxonomy – User segment The User segment contains interfaces and devices that enable end users to access and benefit from the services provided by a satellite, ranging from communication and navigation to TV reception and industrial applications. Depending on the use-case, the scope of the User segment encompasses assets needed to reach the ground station (or the satellite directly) with the request for service, and to receive the communication from the satellite – enabling the Categories defined in the User segment include: • Consumer interfaces include terminals that enable users to interact with the satellite directly or with other ground station segments. Consumer interfaces rely on Very-small-aperture terminals (VSATs), comprised of smaller asset groups that include 64,65 consumer antennas and modems connected to routers for dispersing the signal. • Consumer endpoint devices include the physical assets needed to manage the consumer interfaces. This includes, for example, satellite phones, satellite television receivers, vehicles, industrial systems, aircrafts, etc.

27

SPACE THREAT LANDSCAPE

March 2025

3.4. HUMAN RESOURCES SEGMENT Figure 7: Detailed Asset Taxonomy – Human Resources segment Human Resources comprise the human dimension of the asset taxonomy, embedded across the entire satellite lifecycle. It is the staff’s vigilance and compliance with different security protocols that create an integral layer for protecting mission-critical assets and ensuring security by design and by default throughout the lifecycle. Asset subdomains defined in the Human resources segment are directly related to the actor clusters identified against the different phases of the satellite lifecycle, and include: • Actors participating in development activities; • Actors participating in supporting tasks; and • Actors participating in satellite operations.

28

SPACE THREAT LANDSCAPE

March 2025

4. SPACE THREATS

Satellite systems and related services are an integral component of modern life, supporting a wide range of critical applications, from communications to navigation and Earth observation. Increased reliance on satellite technology also exposes these systems to a growing array of cybersecurity threats. Understanding the threat landscape for satellite systems is therefore crucial for safeguarding their operations and ensuring continued, uninterrupted provision of relevant satellite-based services. This chapter delves into the web of threats facing satellite systems, examining different threat actors, threat categories, and possible tactics, techniques, and procedures (TTPs), compiled in a threat taxonomy. 4.1. SPACE THREAT TRENDS The Space Attacks Open Database Project provides a detailed compilation of publicly known attacks on satellites, covering the period between 1977 and 2019. However, despite the immense growth of the space sector over the past years , there seems to be a lack of consolidated data on cybersecurity incidents taking place during this period. The lack of analysis, together with the lack of control of space-based infrastructure and objects, was also recognised by ENISA’s 2023 Foresight report , listing it in the top 10 threats. Supplementing the Space Attacks Open Database Project findings with additional insight from publicly available reports on individual cybersecurity incidents in the space domain indicates that the majority of the space-based attacks took place on commercial and government targets as illustrated in Figure 8. These are followed by targets on the military and civilian sectors, and one identified attack on state-run media outlets. Due to their nature and spread, some of these attacks contain overlaps in terms of target categories. While the database does not specify differentiators between these categories, it is assumed that the difference lies in the party that actually owns/operates the asset (making the difference between government, civilian, and military). Figure 8: Target categories of known attacks in the space domain

29

SPACE THREAT LANDSCAPE

March 2025

As illustrated in Figure 9 below, attacks on commercial satellite infrastructure have had a consistent presence throughout the observed period. Although the updated ENISA’s 2024 Foresight report no longer lists space-related threats in the top 10, the lack of analysis and th control of space-based infrastructure and objects still figures prominently, taking 11 place. Inspecting technological trends, the report recognises that as the number of satellites in space grows so does our dependency on space infrastructures. Consequently, a rise in the number of attacks against satellites can also be expected. Figure 9: Examples of known attacks on commercial satellite infrastructure/s (timeline) Jamming was among the most frequent materialised threats according to the database, the effects of which can range from disrupting access to a satellite to affecting Global Navigation Satellite Systems (GNSS) used for services such as GPS. followed by hijacking and Computer Network Exploitation (CNE). Attacks aimed at control functions, as well as spoofing, eavesdropping and the employment of anti-satellite weapons (ASATs) were far less frequent

30

SPACE THREAT LANDSCAPE

March 2025

during the observed period. The figure below presents a breakdown of the attack types identified. Figure 10: Breakdown of known attacks on satellites per attack type Visibility of space threat trends is expected to improve with developments such as the obligation to report all significant incidents prescribed by the NIS2 Directive, which now includes space, telecoms in the scope of sectors of high criticality and other relevant critical sectors such as the manufacturing of e.g. computer, electronic and optical products, machinery, transport equipment, and equipment n.e.c. , thereby providing a more complete picture of the threat landscape impacting satellite operations. The recent establishment of the EU Space Information Sharing Centre (ISAC) is also expected to encourage more proactive information and knowledge sharing about security-related information, incidents, cyber trends, vulnerabilities, and threats among commercial space operators. In turn, this will reflect on the number of known incidents, with an expected upward trend compared to previous years as more cyber-relevant events will be officially recorded. 4.2. THREAT ACTORS The growing commercialisation of the space domain opens the door to a wide array of threat actors, motivated by different traits and with varying levels of capabilities, including: State-nexus actors, who rely on government resources to achieve their objectives. Primarily engaged in espionage and disruption, state-nexus actors are sometimes directed by the military, intelligence or state control apparatus of their country and often spend considerable time investigating their targets to identify weaknesses and entry points. In addition to other states, state-nexus actors can also target other organisations for sensitive data or conduct operations to obtain funding for their country.

31

SPACE THREAT LANDSCAPE

March 2025

Cybercrime actors and hacker-for-hire actors, primarily motivated by financial gain. Mainly targeting data or infrastructure, cybercrime actors often employ social engineering and either steal from their victims, engage in extortion, or aim to monetise the stolen information. As a subcategory of cybercrime actors, hacker-for hire actors contribute to the professionalisation of the cybercrime market, including services to state-nexus actors, often providing access to environments or cybercriminal services (e.g. ransomware-as-a-service). Private Sector Offensive Actors (PSOA), who are engaged in the cyber-surveillance industry. Focused on enabling other actors (e.g. governments, private individuals) to gain a competitive advantage against their peers, PSOAs specialise in developing and selling cyberweapons to their clients, equipping them with advanced cyber capabilities. Hacktivists (a.k.a. Civil Activists), whose primary goal is to extract and expose data or disrupt business operations for ideological reasons or to draw attention to a specific cause, advocating for political or social change. Hackers, comprising a diverse set of malicious actors’ subgroups that vary in their motivation, objectives, skillsets and capabilities. These may range from Cyberwarriors and Cyber Fighters to Blackhat hackers/Crackers, but can also include Cyber Vandals and Script Kiddies. Disgruntled Employees or Insider Attackers, who have detailed insight of the organisation and its systems. This includes staff, contractors, vendors, customers, or former employees. Untrained/Reckless Employees, who may not have the intention to cause harm but may still do so as a result of negligence or insufficient training. With the above, different threat actors can exercise various types of attacks regardless of the resources of their supporting organisation - if any. This is further corroborated with examples of different threats, discussed below, which do not necessarily require significant resources to perform successful cyber-attacks. When conducting a risk assessment, the threat actors most relevant for the specific use case should be identified. This involves delving into the characteristics of each identified threat actor category/type, including their motivations, capabilities, and objectives. The provided descriptions are inconclusive and serve as a foundational starting point for a more in-depth analysis. More details on the abovementioned threat actors, their motives, means, and opportunities is provided in the ENISA Threat Landscape 2024 , and in ENISA’s Methodology for Sectoral Cybersecurity Assessment .

32

SPACE THREAT LANDSCAPE

March 2025

4.3. THREAT TAXONOMY METHODOLOGY The taxonomy presented below is based on a comparative analysis of academic and industrial (including relevant government agencies) resources deliberating on the types of threats and attack tactics, techniques, and procedures (TTPs) applicable to the space domain and publicly available information on known attacks on satellite infrastructure. These are then clustered in common threat categories and inspected for their impact on confidentiality, integrity and availability (CIA). As a final step, identified threats are mapped against the relevant asset categories and subdomains identified in Chapter 3. The threat taxonomy strictly focuses on assets for which a direct cyber-relevant threat has been identified, resulting in disruption or destruction of satellite infrastructure and/or services. Assets that are at risk solely from physical threats are not further addressed. Important to note is that there is no universally accepted standard for a threat taxonomy, and competing approaches are still emerging. This is evident in the literature examined for the purpose of this report where classifications of threats and relevant TTPs and attack vectors employed in the materialisation of these threats somewhat overlap. The presented taxonomy therefore focuses on the common threat clusters identified across the addressed information sources, while common TTPs and attack vectors form the parts of the description of these.

33

SPACE THREAT LANDSCAPE

March 2025

4.4. THREAT TAXONOMY For the purpose of the threat taxonomy, high-level threat categories have been derived from ENISA’s threat taxonomy , which serves as a baseline for mapping the space threat landscape. This includes the following threat categories: • Nefarious Activity/Abuse (NAA): “intended actions that target ICT systems, infrastructure, and networks by means of malicious acts with the aim to either steal, alter, or destroy a specified target”. • Eavesdropping/Interception/ Hijacking (EIH): “actions aiming to listen, interrupt, or seize control of a third party communication without consent”. • Physical Attacks (PA): “actions which aim to destroy, expose, alter, disable, steal or gain unauthorised access to physical assets such as infrastructure, hardware, or interconnection”. • Unintentional Damage (UD): unintentional actions causing “destruction, harm, or injury of property or persons and results in a failure or reduction in usefulness”. • Failures or malfunctions (FM): “partial or full insufficient functioning of an asset (hardware or software)”. • Outages (OUT): “unexpected disruptions of service or decrease in quality falling below a required level. • Disaster (DIS): “a sudden accident or a natural catastrophe that causes great damage or loss of life”. • Legal (LEG): “legal actions of third parties (contracting or otherwise), in order to prohibit actions or compensate for loss based on applicable law”. In addition to the above, threats stemming from the legacy infrastructure (LEI) are also present. Although legacy is a challenge for all information technology enabled systems, the nature of space infrastructure - where assets are not physically reachable yet need to provide services at a specified level of output and quality for protracted periods of time, makes this an important feature to consider in relation to the developing cyber threat landscape. The extended 96, 97, 98, 99 use of commercial off-the-shelf software (COTS) for different satellite components adds a further layer of complexity to the management of the satellite infrastructure. Apart from standard supply chain risks resulting from – among other – the reliance on COTS, threats in the context of legacies may materialise via an exploit of vulnerabilities arising during the satellite’s infrastructure lifecycle. Some of these might have been unknown or were not considered as relevant during the design, assembly, and initial operational phases, which may result in unpatched or outdated legacy COTS components . Finally, as an overarching prerequisite for most of the threats identified above, the acquisition of capabilities by adversaries is also recognised as a threat vector by the SPARTA matrix

34

SPACE THREAT LANDSCAPE

March 2025

and the ESA SPACE-SHIELD , both of which are based on the MITRE ATT&CK framework and tailored to the space domain. Acquisition of capabilities refers to the ability of threat actors to acquire and employ the necessary skills and/or resources to achieve their objectives. This may relate to various types of offensive activities aimed at any satellite lifecycle asset, ranging from the acquisition of infrastructure (e.g. ground infrastructure, space infrastructure), to specific software (e.g. advanced malware, decryptors) or tools (e.g. specific anti-satellite assets, such as anti-satellite weapons - ASAT). Figure 11 provides an overview of the high-level threat categories for the space domain. A breakdown of specific threats within each of these categories is presented below in Figure 12. Details on each of the identified threats, their impact on CIA, and respective affected assets is provided in Annex B. Several overlaps of specific threats across the threat categories exist, as these can be a result of both nefarious activities as well as unintentional damage. The threat taxonomy presented in this report is aimed for general applicability for any orbit. Figure 11: Space Threat Taxonomy

35

SPACE THREAT LANDSCAPE

March 2025

Figure 12: Detailed Space Threat Taxonomy

36

SPACE THREAT LANDSCAPE

March 2025

5. RISK ASSESSMENT

This chapter presents three risk scenarios aimed at illustrating the potential impact of adverse events on commercial satellite infrastructure and the services they provide. These hypothetical scenarios consider the defined generic lifecycle model, assets taxonomy and taxonomy of threats as presented in this report. Examples of real-life incidents involving satellite infrastructure, derived from the literature review for preceding steps, have also been taken into account. Each scenario specifies the threat(s) that are materializing, the assets at risk, and the potential threat actor(s) considering generally assumed capacity and possible motivations behind the threat actor clusters. Cascading effects are presented through the escalation path, and impact is considered through the CIA triad, supplemented with wider impact considerations presented in the form of a high-level PESTLE analysis. When conducting a risk assessment, identified relevant threats should be classified considering their impact, likelihood, intentionality, and cascading effects. 5.1. SCENARIO 1: COMMUNICATIONS PROTOCOL COMPROMISE VIA SOCIAL ENGINEERING Assumptions on the context: • Commercial broadcasting satellite (TV and radio). • In-house, on-prem operations centre. • Insufficient staff awareness. • Weak network segmentation. The scenario covers several ground-related threats that can result with an attacker taking control over the Telemetry, Tracking, and Command (TTC) ground station and communication protocols and ultimately hijacking the satellite and/or obtaining the ability to modify mission values. The scenario emphasises the growing risk of satellite hijacking to either disable the satellite or broadcast a malicious signal. As depicted in Figure 14, the first step is to gather information on employees, identify potential targets, and launch a spearphishing campaign in order to secure initial access. A link in the phishing email leads an employee to download a malicious file, which enables the attacker to access the network. Once inside the network, the attacker exploits the lack of segmentation, moving laterally and gaining access to credentials stored in memory. In parallel, the attacker conducts network reconnaissance to identify satellite control systems, configurations, and communications protocols to direct the next attack. The extracted valid credentials are then used to penetrate the mission control software. The attacker thus obtains access to information about configurations and signal amplification mechanisms at one of the TTC ground stations connected to the mission control centre. Access to such information enables the attacker to exfiltrate sensitive data related to satellite communication protocols and encryption keys. Assuming that the systems have a vulnerable SDLS protocol, the attacker can gain access to critical information including Authentication, Encryption, and Authenticated Encryption. As a result of such a vulnerability, the attacker obtains knowledge about data link protocols connecting the operations centre and the TTC ground station enabling either eavesdropping on

37

SPACE THREAT LANDSCAPE

March 2025

the communication or compromising the signal, thus impacting the satellite's confidentiality, integrity, and availability. With control over the mission control software, the attacker can also intentionally crash the satellite, causing physical damage to the satellite itself as well as other satellites in the constellation or further afield. It is important to stress that beyond the owned Ground station and the Ground Station as a Service (GSaaS) models, where ground stations belong to authenticated players, operators may face additional challenges related to ground station security. Open networks like SatNOGS , often supporting open-source missions, rely on voluntary contributions, raising significant concerns about the level of trust that can be placed in such diverse and potentially unverified ground stations. The risk of malicious or compromised ground stations within these networks cannot be discounted. Furthermore, while the focus is often on the communication links between the ground station and the satellite, the security of links and protocols between ground stations is equally critical. These inter-ground station communications, often used for coordination and data sharing, represent another potential attack vector that requires careful consideration and robust security measures. Figure 13: Scenario 1 – Communications protocol compromise via social engineering Table 1: Scenario 1 – Communications protocol compromise via social engineering l ic is ia IMPACT (CIA) ol rin un c oc e ns e m Crucial s : the compromise of communication protocols between the satellite operations centre, TTC g tio prom in a ia ground station, and the satellite itself, grants the attacker access to the majority of assets related to proto om v ng Com c e e satellite operations and mission execution. Once compromised, the attacker can eavesdrop on all

38

SPACE THREAT LANDSCAPE

March 2025

communication, modify onboard values, cause disruption by manipulating the satellite's bus, or continue to penetrate into the satellite bus-payload link and modify the payload to leak confidential information. Compromised communication protocols lead to multiple mission-specific assets being compromised, amounting to a critical impact level with all three CIA categories – confidentiality, integrity, and availability – affected. As this cybersecurity incident looks into the compromise of communication protocols between the ground and satellite infrastructure, impacts on CIA are as follows: CONFIDENTIALITY The breach and compromise of SLE/SDL protocols jeopardises confidentiality of data transmitted between the satellite operations centre, ground stations, and the satellite itself. Sensitive or client privileged information, as well as corporate interests of the satellite operator, become vulnerable to unauthorised access. The ability to eavesdrop on communication channels allows attackers to gather intelligence, which could lead to strategic disadvantages, leak of proprietary technology, as well as commercial espionage. INTEGRITY The ability to laterally move within the network and eventually gain control over communication protocols, both on the ground and in the satellite itself, grants the attacker the ability to disrupt the integrity of satellite services. With access to SLE/SDL protocols the attacker can alter critical parameters and commands to compromise transmitted data. Such activities could lead to incorrect satellite positioning, incorrect sensor readings, and execution of malicious commands. Loss of data integrity has a negative impact on trust in the information transmitted and makes it difficult for operators to distinguish between genuine and manipulated commands and telemetry. AVAILABILITY With the scenario escalating, the attacker can rely on compromised communication protocols to ultimately disrupt the availability of satellite services, as well as the satellite itself. The attacker can hijack the satellite to broadcast malicious signal, as well as crash it or render it inoperable, thus impacting and disrupting the payload and the services provided. As such, compromised availability not only affects the mission itself, but can also trickle down to the sectors relying on the satellite, potentially leading to both financial and legal consequences. THREAT CLUSTER ASSETS AFFECTED THREAT ACTORS • Social Engineering • Untrained/ Reckless • Malicious code/ software/ • Satellite Operations Centre Employees activity: Network exploit • TTC Ground • (Organized) Cyber Crime • Abuse/ Falsification of rights • SLE/SDL actors • Unauthorised access • Satellite bus • State-Sponsored • Interception of • Satellite payload Attackers/Government communication Spies • Hijacking BROADER IMPACT (PESTLE) POLITICAL • Potential for strained relations between countries if the breach is used for promotion of political propaganda via compromised payload or is traced back to state-sponsored groups. ECONOMIC • TV and radio broadcasters, satellite operators and consumers could suffer financial losses due to disrupted services. • The costs of mitigating the attack and restoring services could be substantial. SOCIAL

39

SPACE THREAT LANDSCAPE

March 2025

• It could lead to the disruption of information flow and the public could lose access to important news, potentially leading to misinformation. • Spreading disinformation or propaganda can lead to social unrest. ENVIRONMENTAL • The incident may raise concerns of space debris if the corrupted satellite becomes uncontrollable or changes trajectory. ESCALATION PATH 1. The attacker gathers information on the satellite centre’s employees and selects possible targets for a spearphishing campaign. 2. The attacker sends spearphishing emails containing malicious attachments to the selected employees of the satellite control centre. One employee that opens the attachment, would trigger malware payload. With this, the attacker would establish an initial foothold in the facility’s internal network. 3. The attacker could further exploit vulnerable systems and the lack of network segmentation to access credentials stored in memory and conduct credentials dumping. 4. Credentials are then extracted, including details on privileged accounts within the network. The attacker filters valid credentials that are associated with satellite control systems. 5. The attacker then conducts network reconnaissance to identify satellite control systems, configurations, and communications protocols, which are later used to gain control over TTC ground stations and antennas. 6. The attacker utilises valid credentials to move laterally within the network and access the mission control software. 7. The attacker collects information about the satellite communication equipment – specifically, the antenna configurations and signal amplification mechanisms at one of the TTC ground stations connected to the mission control centre. 8. The attacker manages to exfiltrate sensitive data related to satellite communication protocols and encryption keys, therefore gaining the ability for corrupting SLE/SDL protocols between the operations centre, the TTC ground station, and the satellite. Eventually, the attacker could corrupt the satellite bus and payload. 5.2. SCENARIO 2: EXPLOITING OBC/OBSW VULNERABILITIES VIA MALICIOUS CODE Assumptions on the context: • Commercial satellite constellation providing internet coverage (broadband satellite service). • Weak perimeter protection (assembly and/or transportation) and, in case these are provided by third parties, lack of vendor/third party security audit and due diligence. • Weak hardening procedures after the assembly phase. • Weak software configuration and data processing controls. This scenario covers several ground – and space – related threats designed to take control over the satellite bus and specifically On-Board Controller (OBC), On-Board Software (OBSW), and subsequently the Real Time Operating System (RTOS). The scenario emphasises the threat of unauthorised physical access that can be exploited to plant malicious software which can corrupt satellite’s operations and on-board system once in orbit. Hence, the scenario points out oversights such as inadequate hardening procedures after assembly, which allow for an IO device (for example a USB drive) to be plugged in and transfer malicious code. Finally, the scenario showcases how software misconfiguration during production leads to vulnerabilities, ultimately enabling threat materialisation during operations. For this threat to materialise, the attacker first needs to gain unauthorised physical access to the satellite’s assembly line or transport container to implant malicious code using an IO interface (e.g. a USB port) to install malicious software modelled to exploit existing vulnerabilities caused by software misconfigurations in the OBC and OBSW. Specifically, as satellite systems process

40

SPACE THREAT LANDSCAPE

March 2025

large quantities of data, the malware prevents sanitisation of data inputs manipulating the OBC and OBSW by injecting random and inconsistent data. The malicious data eventually creates errors in the RTOS system. The repetitive requests caused by the malware would lead to compromise of the logical storage, which would reach its full limit by causing resource exhaustion. This enables the attacker to modify the satellite’s parameters opening new opportunities for further tampering with its reset and update procedures. With the ability to modify parameters, the attacker can compromise the TM/TC data at the satellite’s COM and attempt to hijack the satellite or engage in eavesdropping. Meanwhile, unable to detect the source of such erratic behaviour of the satellite’s bus and find a way to correct it, the mission control centre ultimately loses control of the space segment. Figure 14: Scenario 2 – Exploiting OBC/OBSW vulnerabilities via malicious code Table 2: Scenario 2 – Exploiting OBC/OBSW vulnerabilities via malicious code IMPACT (CIA) ia e BSW v Crucial: the injection of random and inconsistent errors into the satellite’s system creates a highly s od C/O e c unpredictable operational environment, compromising the satellite’s reliability and overall performance. iti s il Due to software misconfiguration in the space segment, the ground team is unable to efficiently identify OB g iou rab c and patch the vulnerability until the point when it is too late for any restart to occur due to resource tin li ne a exhaustion. Combined with communication failures and system malfunctions this would result in oi ul m pl v significant disruption of the satellite’s services, affecting integrity and availability. Ultimately, attackers Ex can exploit other assets such as COM, and impact confidentiality and availability of the satellite.

41

SPACE THREAT LANDSCAPE

March 2025

As this cybersecurity incident looks into the compromise of satellite BUS, impacts on CIA are as follows: CONFIDENTIALITY If the TM/TC data at the satellite’s COM is compromised, interception of communication is enabled allowing the attacker to engage in eavesdropping, thus violating data confidentiality. INTEGRITY The malware’s continuous presence and manipulation of the satellite’s software results in an unpredictable operational environment and compromised data integrity. As the software transmits corrupted telemetry and executes malicious commands, decision-making at the mission control centre can be incorrect. Due to the resource exhaustion and challenges in resetting the satellite, the mission control centre cannot discern false readings and manipulated data from genuine ones, ultimately jeopardising the trustworthiness of the space segment. AVAILABILITY The persistent malware corrupting the data ultimately exhausts the system’s resources and memory, rendering the satellite inoperable. As the satellite’s performance deteriorates, computational sensing becomes unreliable or ceases altogether. As the scenario escalates, the attacker may compromise other assets such as COM to hijack the satellite or crash it. THREAT CLUSTER ASSETS AFFECTED THREAT ACTORS • Unauthorised physical access • Sabotage through hardware/software • Malicious code/ software/ • State-Sponsored • Assembly/Manufacturing activity: Software and Attackers/ Government systems/Transport vulnerabilities' exploit Spies container • Software misconfiguration • Cyber Terrorists • Satellite BUS (OBC, • Resource exhaustion • Disgruntled Employees or OBSW, RTOS, COM) • Unauthorised modification: Insider Attackers Parameters • Seizure of control: Satellite bus • Hijacking BROADER IMPACT (PESTLE) POLITICAL • Depending on the beneficiaries of the satellite providing internet coverage, political concerns could arise if the attacker was to use it for espionage or communication sabotage. • Political implications could also arise if the malicious actor gaining unauthorised physical access was found to be working on behalf of another country. SOCIAL • In remote or conflict-affected areas where alternative communication infrastructure is limited could hinder emergency response effort as well as access to potentially life-saving information. • A collapse of internet-providing satellites would create an information vacuum, leading to uncertainty and potential panic. TECHNOLOGICAL • Services that rely on the internet, from streaming to cloud computing, would be unavailable. • Potential disruptions in any autonomous systems relying on internet connection.

42

SPACE THREAT LANDSCAPE

March 2025

ENVIRONMENTAL • Losing control of the space segment could potentially contribute to the creation of space debris in a situation where a threat actor taking control of a satellite would change its course and cause it to collide with another satellite. ESCALATION PATH 1. The attacker gains unauthorised physical access to the satellite’s assembly line or transport container and implants malicious code via the satellite’s USB port. 2. The malware exploits computational systems, including OBC and OBSW, which are vulnerable to common software faults. 3. Once the satellite is in orbit and begins to process large quantities of data, the malware triggers malicious injection into OBC & OBSW injecting random and inconsistent errors into the system. 4. The malware compromises logical storage, until the full limit is reached, and then modifies the satellite's parameters enabling further tampering with its reset and update procedures. 5. As a result of the above, malware causes the satellite to continue to operate with random errors, causing persistent unreliability, with the source of the errors undetected, malware maintains control and disrupt satellite functionality. 6. Ultimately, the malware compromises space assets by exploiting existing vulnerabilities, while the security teams struggle to identify the source of errors, leaving them without clear evidence of malicious software implanted during ground operations. 7. As a result of the software misconfiguration and the inability of security teams to patch the vulnerability, the scenario can escalate where the attacker ultimately gains control of the satellite. 5.3. SCENARIO 3: NETWORK INTRUSION DUE TO A LACK OF SECURITY PROTOCOLS AND MISCONFIGURATION Assumptions on the context: • Commercial navigation satellite that is part of a low Earth orbit (LEO) satellite. constellation providing positioning, navigation, and timing (PNT) signals. • Subpar incident/natural disaster response plan. • Ignoring security procedures for adding COTS in production environment (operations) in favour of business continuity. The scenario covers several ground-related threats that emphasise how improper security planning and ignoring security procedures combined with environmental hazards could be used by attackers to gain access to VSATs to eavesdrop on confidential information, leak or corrupt the data, or even corrupt firmware to launch ransomware attacks. The scenario emphasises how growing risks of environmental hazards, such as fires and floods, coupled with subpar security planning and compliance, can disrupt the secure communication chain between the satellite and the end-users. A major hailstorm has seriously damaged a terminal ground station of a commercial satellite operator providing navigation services. Namely, the company’s VSAT antennas have been badly affected, causing failure of services provided to end users in a specific region. Since the company does not employ a mesh network, it is forced to acquire a new set of VSATs as a means of quickly restoring services. New VSATs are procured through a trusted third-party provider and are immediately put into operational use to cut any financial losses. Thus, with business continuity placed before security, the conduct of necessary hardening of the acquired infrastructure is skipped. However, the company’s IT team quickly discovers a vulnerability within the newly acquired network infrastructure, allowing for remote code execution. Specifically, unused ports on the VSATs modem unit are not configured as per the manufacturer's recommendations and are left open for accepting packets. As the new VSAT are already being installed, the management is faced with the decision whether to first shut down the network before it is patched (it needs to be patched in multiple places and properly tested, with further security procedures carried out); patch immediately without proper testing; or keep

43

SPACE THREAT LANDSCAPE

March 2025

business as usual until the patch is ready and deployed. The management realises that another shutdown of operations will cause further disruption and financial losses and opts for the second option - patching without testing. This leaves the ports open and with no testing performed undetected, and creating a potential entry point for malicious actors. This vulnerability is picked up by a malicious actor during a random port scanning. The malicious actor exploits this misconfiguration to tap into the network, realising further weaknesses in the form of improper network segmentation, allowing smooth lateral movement across mission critical satellite components. This enables the attacker to intercept communication between the newly deployed VSATs and the end users. Having this access enables the attacker to leak collected data, corrupt it, launch subsequent man-in-the-middle attacks or implant ransomware by corrupting the VSAT firmware. In a worst-case scenario, combined with weak network segmentation, the attacker can even reach and compromise the systems of end users relying on the affected VSATs in case weak network segmentation is also present on the receiving (end user) end. Figure 15: Scenario 3 – Network intrusion due to a lack of security protocols and misconfiguration Table 3: Scenario 3 – Network intrusion due to a lack of security protocols and misconfiguration e ti IMPACT (CIA) f nd du o a ura n k s c Crucial: as a result of natural disasters, the lack of, or subpar, incident response plan leads to “quick fix” urity ol fig io on la c solutions where business continuity is placed ahead of security. With this, introduction of new equipment c a e on Network s c trus to also highlights the need for complying to the security programme and clear guidelines on controls for is in proto m securing COTS. A failure to comply to security controls and harden COTS, increases the likelihood of

44

SPACE THREAT LANDSCAPE

March 2025

different ports being left open on VSAT’s modem and router. Scanning ports to check which ones are open, is not a complex task and does not require any significant skills, resulting in a myriad of potential attackers (from “script kiddies” to state-sponsored groups). Furthermore, the assumption that the network is not properly segmented, enables the attacker to freely move around systems and target specific protocols - such as communication between the provider of the service and the user in this case. This scenario showcases how ignoring compliance and security procedures in favour of business continuity results with an attacker being able to eavesdrop on the communication, as well as have the ability to leak the client-privileged data, use it to launch man-in-the-middle attacks against the users, or corrupt firmware of the VSAT to potentially engage in ransomware attack. CONFIDENTIALITY The attacker’s ability to access the network and eavesdrop on the communication between the service provider (VSAT) and the end-users, compromises confidentiality. The attacker can gain access to sensitive information such as intellectual property, credentials, and proprietary data. Leaking this data can be exploited for malicious purposes. INTEGRITY With access to the VSATs, attackers can perform mad-in-the-middle attacks, given the ability to modify and corrupt data exchanged between the service provider and the users. Access to VSATs enables attackers to deceive users, manipulate certain transactions, and inject malicious content. This can lead to issues such as fraud, misinformation, legal actions against the VSAT provider, and loss of customer base due to eroded trust in the former’s systems. AVAILABILITY With the ability to corrupt firmware, attackers can move laterally across the network and exploit this to access additional systems and solutions. Such capability is likely to lead to ransomware attacks where attackers encrypt essential data and disrupt the functionality of the systems. THREAT CLUSTER ASSETS AFFECTED THREAT ACTORS • Environmental Hazard • Software misconfiguration • Malicious code/ software/activity: Network • (Organised) Cyber Crime exploit • TTC Ground - VSAT - actors • Unauthorised access Antenna • Blackhat • Compromising confidential • User VSAT Hackers/Crackers information (data breaches): • User Endpoint Devices • Cyber Vandals/Cyber Exfiltration Punks • Man-in-the-Middle • Abuse of leaked data • Firmware corruption BROADER IMPACT (PESTLE) ECONOMIC • Economic losses in sectors reliant on precise navigation (e.g. shipping, aviation, ride-sharing). • Financial losses for satellite-based service providers due to service disruptions and loss of customer trust. SOCIAL • Public dismay in societies highly reliant on PNT, especially if key services like navigation, communications, or emergency services are affected. ESCALATION PATH

45

SPACE THREAT LANDSCAPE

March 2025

1. An environmental disaster damages VSAT antennas providing services to a specific region. 2. The company scatters to quickly replace these, disregarding security protocols for hardening the devices, including modems and routers connected to the VSATs. 3. An attacker scanning for open ports identifies this vulnerability and takes advantage of it, gaining unauthorised access into the network. 4. Once within the network, the attacker has the ability to conduct reconnaissance and or prepare for subsequent eavesdropping or attacking campaigns. 5. Weak network segmentation allows the attacker lateral movements across mission critical components, posing as a threat to end users as well in case the latter’s network is not properly segmented/patched/secured. 6. The ability to eavesdrop on the communication exchange between the VSAT and the end-user, provides the attacker with the opportunity to leak confidential information. 7. The attacker also gains the ability to conduct man-in-the-middle attacks, to corrupt the data exchanged between the subject company and its clients, or to launch subsequent ransomware attacks by corrupting firmware.

46

SPACE THREAT LANDSCAPE

March 2025

6. CYBERSECURITY CONTROL FRAMEWORK

This chapter aims to provide clear and concise recommendations on the implementation and use of appropriate cybersecurity controls, presented in the form of a sample cybersecurity control framework. The listed controls are derived from existing EU regulations , international cybersecurity frameworks , cybersecurity profiles tailored to the space sector , best practice guides , taxonomies of countermeasures , and national guidelines . They are mapped against specific threats identified in the threat taxonomy and applied across relevant phases of the lifecycle. Aiming for general applicability, the controls can be further tailored depending on the nature and needs of a specific mission. In total, the control framework contains 125 individual controls, grouped into 18 control clusters. These are: • Policies and procedures: addressing the governance aspects of space missions in the context of cybersecurity. The objective is to ensure that relevant information and cyber security processes are in defined, documented, approved by management, communicated to all relevant parties and, ultimately, implemented. Having clear policies and procedures in place ensures that all stakeholders are aware of the security requirements, as well as their obligations, roles, and responsibilities for implementing and/or adhering to these. • Compliance: addressing the wider business environment of satellite operators in relation to legal and regulatory requirements. These include sector-specific regulations and requirements for critical entities, as well as obligations related to protection of privacy and intellectual property rights, and extra-territorial jurisdiction. An important component of verifying and maintaining compliance are independent reviews of information security (audits) to identify any gaps and relevant mitigation measures. • Risk management: addressing how risks are identified, assessed, and mitigated throughout the lifecycle. Controls in this cluster include threat modelling to identify the

47

SPACE THREAT LANDSCAPE

March 2025

attack surface, criticality analysis to determine critical functions and data flows and prioritise mitigation measures, and Business Impact Analysis (BIA) to assess the potential impact and likelihood of identified threats. The objective is to establish a comprehensive risk management framework, including Third Party (supply chain) risk management practices. • Security by Design and by Default: promoting Secure Development Lifecycle (SDLC) practices and the principles of security by design and by default. Controls in this cluster address aspects of coding standards and configuration management, change management and separation of environments to prevent lateral movement in case of a breach. • Environmental and Physical security: primarily aimed at ensuring physical protection of ground segment infrastructure and satellite components during transport to prevent unauthorised access and tampering. • Network security: primarily aimed at supporting the establishment of resilient communication flows. Controls in this cluster include access-based segmentation of the network, authenticated encryption (with associated data), and disabling physical ports and non-critical backdoor commands, among others. The objective is to establish and maintain the integrity and confidentiality of communication. • Data security: addressing the confidentiality, integrity, and availability of data in all forms (rest, transit, use), throughout the information lifecycle. Controls in this cluster include identification of information assets, classification, and labelling, as well as measures for Data Loss Prevention (DLP) and ensuring a defined process for backup. • Vulnerability management: aimed at ensuring that technical vulnerabilities are identified, validated and recorded and that there are defined processes to address these. Controls in this cluster address aspects such as vulnerability scanning, malware 119 120 protection, software and protocol updates , integrity checks and assurance, and prevention against installation of unauthorised software. • Access management (zero trust): aimed at ensuring data and information system confidentiality and integrity, preventing unauthorised access. Controls in this cluster address aspects of identity management, access rights, authentication and authorisation and session termination, among others. The cluster accounts for both physical and logical access management practices and is built on zero-trust principles, including least privilege and verification of all access requests (internal and external) prior to granting access to the network and other assets. • Asset management: concerned with appropriate management of assets throughout their lifecycle, including systems, hardware, software, services, and data. Controls in this cluster include establishment and maintenance of an up-to-date asset inventory, prioritisation of assets based on their classification, criticality, resources, and impact on

48

SPACE THREAT LANDSCAPE

March 2025

the mission, and resulting security requirements such as maintenance, return, and secure disposal or re-use of equipment. • Supply Chain management: aimed at ensuring resilience of the supply chain including outsourced developments, provision of services, as well as procurement and use of COTS. Controls in this cluster include the use of Service Level Agreements (SLAs) to define and monitor Third Party adherence to defined obligations, measures to ensure supply chain security, as well as to ensure that third party software and hardware can be analysed for known vulnerabilities to inform further actions. • Monitoring and Alerting: aimed at ensuring that mission critical components or systems and logs are monitored on a continuous basis to enable timely alerting in case of suspicious or anomalous activity, feeding into response capabilities. Good practice and controls in this domain include network and communications monitoring, intrusion detection and prevention measures and tools, as well as the deployment of Security Information and Event Management (SIEM) solutions. • Incident Response: aimed at establishing baseline capabilities for responding to detected events and incidents to contain and/or mitigate malicious activity. Controls in this cluster include defining incident thresholds to inform required actions, incident response procedures in the form of an Incident Response Plan, as well as considerations of how information on a detected incident is communicated to relevant stakeholders and the public, as required. • Business Continuity Management/Disaster Recovery: aimed at supporting continuity of critical operations in case of disruption, and/or a return to normal operations following an incident. Controls in this cluster include having defined requirements for critical services delivery, as well as sufficient capacity, redundancy and/or backup options to ensure availability. • Capacity building: addressing the human resources segment, controls in this cluster aim to ensure that relevant stakeholders are provided with sufficient knowledge and awareness to perform their tasks while maintaining vigilance in relation to cybersecurity threats and risks. This includes training and awareness raising measures, as well as collecting cyber threat intelligence and information sharing. • Testing: aimed at ensuring that the processes and procedures in place, as well as the software and hardware deployed are regularly tested to ensure that, once implemented, these function as expected. Testing is an important component of the control framework as it enables proactive identification of gaps that needs to be addressed. Controls in this cluster include testing detection processes, simulations of attack scenarios, software and hardware testing and code analysis, among others. • Continuous improvement: applicable to all aspects of the lifecycle, this control cluster promotes employing feedback loops in terms of feeding the results of testing, reviews and audits back into the existing cybersecurity framework to ensure existing processes are proactively improved. • Defence capabilities: primarily aimed at establishing active defence capabilities to respond to attacks. Controls in this cluster include capabilities such as manoeuvrability, use of deception and decoys, and measures to protect filters, shutters, but also antenna nulling and the use of defensive jammers and spoofers.

49

SPACE THREAT LANDSCAPE

March 2025

6.1. CONTROLS TO THREATS MAPPING The tables below provide a mapping of relevant cybersecurity controls to each of the threats clusters and threats identified in the Threat Taxonomy. A description and more details on each of the controls making up the Control Framework is provided in Annex D. 6.1.1. Controls for addressing threats from nefarious activity/abuse (NAA) Table 4: Controls for addressing threats from nefarious activity/abuse (NAA) THREAT CONTROL TITLE CONTROL

Legal, statutory, regulatory, and Legal, statutory, regulatory, and contractual requirements relevant to ed contractual requirements information security and the organization’s approach to meet these ak requirements are identified, documented, and kept up to date.

le a

Independent review of Independent review(s) of information security (auditing) are conducted

of dat

information security Data Loss Prevention Data Loss Prevention (DLP) solutions and measures are employed

buse

A OSAM Dual Authorization Multi-factor authentication is employed for OSAM servicers Threat modelling Threat modelling is employed to identify and reduce the attack surface Risk management Risk management processes and procedures are defined and implemented Installation of software on Procedures for software installation on operational systems are defined and operational systems implemented Computing Device Computing devices are authenticated before network connections are Authentication established Access control Access control policies and procedures are defined and documented Identity management Identities are managed throughout their lifecycle Authentication information Allocation and management of authentication information governed by a management management process, including guidance for personnel on proper handling. Access rights Access control policies and procedure determining access rights to information ghts and associated assets are defined and implemented ri Authentication Authentication procedures are defined and documented

of

Multi factor authentication The zero-trust concept is applied to access management

n

io Insider Threat Protection Insider Threat procedures and guidelines are defined and documented at Restricted zones access Informal meeting places within restricted zones are defined

ic

if Password security A password policy and guidelines are defined and documented

ls

fa Asset Inventory An asset inventory if established and maintained

/

Return of assets A procedure for asset management following termination of cooperation is defined and documented

buse

A Continuous Personnel Personnel activity is monitored to detect anomalous behaviours Monitoring Cybersecurity awareness and Cybersecurity is included in human resources practices and personnel are training provided with awareness and training OSAM Dual Authorization Multi-factor authentication is employed for OSAM servicers

Simulation Testing The resilience of segments is tested using attack simulations across the lifecycle Process ID whitelisting Process ID whitelisting is employed in the satellite

Communications Security Secure communication protocols are employed to prevent unauthorized disclosure of, and detect changes to information Information classification and Information is classified according to the assessed risk level and confidentiality, labelling integrity, and availability needs (CIA), and labelled accordingly l ): Data Management Data is protected in all states (rest, transit, use) ia Data Loss Prevention Data Loss Prevention (DLP) solutions and measures are employed

hes

Backup There is a defined and implemented process for conducting, maintaining, and

ident ac

testing backup of information

nf bre

on Information Lifecycle Information assets are identified and described across their lifecycle,

co a ti

g considering all relevant processes

dat tra in ( il

is Data masking Data masking is employed to obfuscate original, sensitive data

xf m ion E

Real-time physics model-based Real-time physics model-based system is used to verify data input and control

at

pro m system verification sequence changes om or Protocol Update / Refactoring Protocols are updated based on emerging threats and vulnerabilities

C inf

Integrity Checking and Integrity checking mechanisms are used to verify software, firmware, and Assurance information integrity

50

SPACE THREAT LANDSCAPE

March 2025

Return of assets A procedure for asset management following termination of cooperation is defined and documented Equipment maintenance Procedures and processes for equipment maintenance are defined and implemented Secure disposal or re-use of Procedures and processes for disposal/re-use of equipment are defined and equipment implemented Asset lifecycle management Guidelines and procedures for the asset management lifecycle are defined and documented Network and Communications Communications are monitored to identify cybersecurity events and verify the Monitoring Function effectiveness of protective measures Reinforcement Learning A reinforcement learning agent is deployed to detect anomalous events Security Information and Event Logs of security-relevant events are integrated into a Security Information and Management (SIEM) / Security Event Management (SIEM) system Operations Center (SOC) Network and Communications Communications are monitored to identify cybersecurity events and verify the Monitoring Function effectiveness of protective measures System redundancy & backup Redundancy is introduced for critical infrastructure and data is backed up e ) Capacity to ensure availability The required level of availability and capacity for the ground segment is

of

al ic maintained and established

oS

eni erv (D Secure Development Lifecycle Rules for the secure development of software and systems should be

D S

established and applied. Tamper Protection Physical inspection of hardware is performed to identify potential tampering

Disable Physical Ports Physical ports are disabled prior to operations

Resilient Position, Navigation, Authentication mechanisms to verify GNSS information sources are in place and Timing Communication Physical Alternate physical mediums for networking are in place to mitigate network Medium security concerns Traffic Flow Security Traffic flow security and confidentiality measures are in place to mitigate traffic analysis attacks On-board Message Encryption Encryption of the message and the space link Secret Shares Secret shares are employed Data encryption Transmitted data (bus-payload link) is encrypted Information classification and Information is classified according to the assessed risk level and confidentiality, labelling integrity, and availability needs (CIA), and labelled accordingly Data Management Data is protected in all states (rest, transit, use) Data Loss Prevention Data Loss Prevention (DLP) solutions and measures are employed Backup There is a defined and implemented process for conducting, maintaining, and testing backup of information on Information Lifecycle Information assets are identified and described across their lifecycle, ti considering all relevant processes

ca

fi Real-time physics model-based Real-time physics model-based system is used to verify data input and control di system verification sequence changes Mo Process ID whitelisting Process ID whitelisting is employed in the satellite

a at

D A tamper resistant body A tamper resistant body is used when producing a sensor node Integrity Checking and Integrity checking mechanisms are used to verify software, firmware, and Assurance information integrity Remote access management Remote access management procedure and processes are defined and documented Secure disposal or re-use of Procedures and processes for disposal/re-use of equipment are defined and equipment implemented Asset lifecycle management Guidelines and procedures for the asset management lifecycle are defined and documented Cloud Cybersecurity Measures SLAs are in place external services and cloud providers

Network and Communications Communications are monitored to identify cybersecurity events and verify the Monitoring Function effectiveness of protective measures Event detection communication Event detection is communicated to stakeholders Anomaly detection Event data is correlated from multiple sources and communicated; Inappropriate or malicious activity within the mission’s systems is detected Mission Cyber Actor Actions An on-board cyber actor actions detection function is in place Detection Reinforcement Learning A reinforcement learning agent is deployed to detect anomalous events

51

SPACE THREAT LANDSCAPE

March 2025

Incident Thresholds Incident thresholds are defined and documented based on an understanding of potential impact Cabling security A secure cabling protocol is defined Information sharing Information is actively shared to achieve broader cybersecurity situational awareness Machine Learning Data Integrity Data integrity testing is performed on AI/ML training datasets Detection Processes Detection processes are continuously improved Filtering and Shuttering Filters and shutters are employed to protect sensors from laser dazzling and blinding Anti-counterfeit Hardware Anti-counterfeit policy and procedures are defined and implemented

Deception and Decoys Deception and decoys are employed for defensive capabilities Coding Standard Secure coding principles for software development are defined and implemented to ensure proper security constructs are in place

ic nce ro ct ere le agnet E erf m int

Cybersecurity-Safe Mode Secure vehicle fault management functions and safe mode operations are implemented to enable a cyber-safe mode when threats are detected

n

Installation of software on Procedures for software installation on operational systems are defined and operational systems implemented

uptio

Vulnerability scanning Vulnerability scanning is used to identify vulnerabilities

orr

c Software Updates Regular software updates are performed to mitigate exploitation risk

re

Integrity Checking and Integrity checking mechanisms are used to verify software, firmware and

wa

Assurance information integrity

rm

Dynamic Code Analysis Dynamic Code Analysis is performed to identify software/firmware weaknesses

Fi

and vulnerabilities Secure Workload-to-Workload Procedures for secure authentication integration protocol are defined and Authenticator documented

Threat modelling Threat modelling is employed to identify and reduce the attack surface Risk management Risk management processes and procedures are defined and implemented Installation of software on Procedures for software installation on operational systems are defined and operational systems implemented Computing Device Computing devices are authenticated before network connections are Authentication established Access control Access control policies and procedures are defined and documented

Identity management Identities are managed throughout their lifecycle Authentication information Allocation and management of authentication information governed by a management management process, including guidance for personnel on proper handling. Access rights Access control policies and procedure determining access rights to information and associated assets are defined and implemented

t

Authentication Authentication procedures are defined and documented

Thef

Multi factor authentication The zero-trust concept is applied to access management

y it

Insider Threat Protection Insider Threat procedures and guidelines are defined and documented Restricted zones access Informal meeting places within restricted zones are defined

Ident

Password security A password policy and guidelines are defined and documented Asset Inventory An asset inventory if established and maintained Return of assets A procedure for asset management following termination of cooperation is defined and documented Equipment maintenance Procedures and processes for equipment maintenance are defined and implemented Continuous Personnel Personnel activity is monitored to detect anomalous behaviours Monitoring Cybersecurity awareness and Cybersecurity is included in human resources practices and personnel are training provided with awareness and training OSAM Dual Authorization Multi-factor authentication is employed for OSAM servicers Simulation Testing The resilience of segments is tested using attack simulations across the lifecycle Transmission security Transmission security solutions and measures are employed to protect communication transmission

52

SPACE THREAT LANDSCAPE

March 2025

Cryptography & Crypto Key Rules for the use of cryptography are defined and implemented; On-board Management messages are encrypted Critical Telemetry Points Critical telemetry points are monitored for malicious activities Monitoring Space-Based Radio Frequency Space-based RF mapping is in place to monitor and analyse the RF ing Mapping environment

m

Defensive Jamming and Jammers and spoofers are employed for defensive operations

m

Ja Spoofing Antenna Nulling and Adaptive Antenna nulling and adaptive filtering are employed for defensive operations Filtering Adaptive Risk Response and Continuous process of qualitative and quantitative mission security risk Resource Allocation Function analysis and risk response is conducted for the duration of the mission Risk management Risk management processes and procedures are defined and implemented Cybersecurity-Safe Mode Secure vehicle fault management functions and safe mode operations are implemented to enable a cyber-safe mode when threats are detected

y:

it Transport Security Transport from the integration hall to the test stations, between different

iv

t facilities, and to the start facility is secured

ct

/a oi Communications Security Secure communication protocols are employed to prevent unauthorized

re pl

disclosure of, and detect changes to information

ex

twa c Cryptography & Crypto Key Rules for the use of cryptography are defined and implemented; On-board sof Management messages are encrypted

/

On-board Message Encryption Encryption of the message and the space link ode ographi Power Masking Power masking is used to protect secret keys

c pt

Satellite Unit RF Encryption Encryption of RF link

ry

ious C Data encryption Transmitted data (bus-payload link) is encrypted ic Data Loss Prevention Data Loss Prevention (DLP) solutions and measures are employed Mal Vulnerability Management Vulnerability management processes and procedures are defined and implemented Threat modelling Threat modelling is employed to identify and reduce the attack surface Criticality Analysis Criticality analysis is performed to identify critical functions, components, and data flows Cybersecurity-Safe Mode Secure vehicle fault management functions and safe mode operations are implemented to enable a cyber-safe mode when threats are detected Backdoor Commands Non-critical backdoor commands are disabled Resilient Position, Navigation, Authentication mechanisms to verify GNSS information sources are in place and Timing Access-based network The network is segmented into subnetworks to prevent unauthorised access segmentation

n

o Data encryption Transmitted data (bus-payload link) is encrypted

ti

Malware Protection Mission operated systems employ malicious code protection mechanisms to

ec

detect and eradicate malicious code

inj

Installation of software on Procedures for software installation on operational systems are defined and ious operational systems implemented ic Software Updates Regular software updates are performed to mitigate exploitation risk

Protocol Update / Refactoring Protocols are updated based on emerging threats and vulnerabilities

Mal

y: Network and Communications Communications are monitored to identify cybersecurity events and verify the

it

iv Monitoring Function effectiveness of protective measures ct Event detection communication Event detection is communicated to stakeholders

/a

re Mission Cyber Actor Actions An on-board cyber actor actions detection function is in place Detection

twa

Reinforcement Learning A reinforcement learning agent is deployed to detect anomalous events

sof /

Incident Response Plan Procedures and processes for Incident Response are defined and documented

ode

c Incident Thresholds Incident thresholds are defined and documented based on an understanding of potential impact

ious

ic Incident Recovery Plan Procedures and processes for Incident Recovery are defined and documented

Mal Critical Services Delivery Resilience requirements to support delivery of critical services are established Requirements for all operating states Static Code Analysis Static Code Analysis is performed to identify system-relevant weaknesses

Deception and Decoys Deception and decoys are employed for defensive capabilities Antenna Nulling and Adaptive Antenna nulling and adaptive filtering are employed for defensive operations Filtering

53

SPACE THREAT LANDSCAPE

March 2025

Secure Workload-to-Workload Procedures for secure authentication integration protocol are defined and Authenticator documented Threat modelling Threat modelling is employed to identify and reduce the attack surface Criticality Analysis Criticality analysis is performed to identify critical functions, components, and data flows Adaptive Risk Response and Continuous process of qualitative and quantitative mission security risk Resource Allocation Function analysis and risk response is conducted for the duration of the mission Risk management Risk management processes and procedures are defined and implemented

Configuration Management Configurations, including security configurations, are defined, documented, implemented, monitored, and reviewed. Cybersecurity-Safe Mode Secure vehicle fault management functions and safe mode operations are implemented to enable a cyber-safe mode when threats are detected Change Management Change management procedures are defined and documented

Tamper Protection Physical inspection of hardware is performed to identify potential tampering Communications Security Secure communication protocols are employed to prevent unauthorized disclosure of, and detect changes to information Transmission security Transmission security solutions and measures are employed to protect communication transmission Disable Physical Ports Physical ports are disabled prior to operations

Backdoor Commands Non-critical backdoor commands are disabled it Resilient Position, Navigation, Authentication mechanisms to verify GNSS information sources are in place

o

and Timing

xpl

e Smart Contracts Smart contracts are used to enforce security protocols

Communication Physical Alternate physical mediums for networking are in place to mitigate network

work

et Medium security concerns N Traffic Flow Security Traffic flow security and confidentiality measures are in place to mitigate traffic

y:

it analysis attacks

iv

Access-based network The network is segmented into subnetworks to prevent unauthorised access

ct

/a segmentation re Cryptography & Crypto Key Rules for the use of cryptography are defined and implemented; On-board twa Management messages are encrypted sof On-board Message Encryption Encryption of the message and the space link

/

Secret Shares Secret shares are employed ode Satellite Unit RF Encryption Encryption of RF link

c

Data encryption Transmitted data (bus-payload link) is encrypted ious Malware Protection Mission operated systems employ malicious code protection mechanisms to ic detect and eradicate malicious code Mal Vulnerability scanning Vulnerability scanning is used to identify vulnerabilities Computing Device Computing devices are authenticated before network connections are Authentication established Remote access management Remote access management procedure and processes are defined and documented Intrusion Detection and On-board Intrusion detection/prevention systems (IDP/IPS) are employed to Prevention detect and respond to threats and attacks Anomaly detection Event data is correlated from multiple sources and communicated; Inappropriate or malicious activity within the mission’s systems is detected Incident Response Plan Procedures and processes for Incident Response are defined and documented Incident Thresholds Incident thresholds are defined and documented based on an understanding of potential impact Incident Recovery Plan Procedures and processes for Incident Recovery are defined and documented

Cabling security A secure cabling protocol is defined Critical Services Delivery Resilience requirements to support delivery of critical services are established Requirements for all operating states Capacity to ensure availability The required level of availability and capacity for the ground segment is maintained and established Detection Processes Detection processes are continuously improved

Deception and Decoys Deception and decoys are employed for defensive capabilities Assessment & Authorization Assessment & Authorization (A&A) procedures and processes are defined and concept documented

54

SPACE THREAT LANDSCAPE

March 2025

Threat modelling Threat modelling is employed to identify and reduce the attack surface Criticality Analysis Criticality analysis is performed to identify critical functions, components, and data flows Coding Standard Secure coding principles for software development are defined and implemented to ensure proper security constructs are in place

Secure Development Lifecycle Rules for the secure development of software and systems should be established and applied. Cybersecurity-Safe Mode Secure vehicle fault management functions and safe mode operations are implemented to enable a cyber-safe mode when threats are detected Separation of Environments The development, testing and production environments are separated and secured Change Management Change management procedures are defined and documented

Access-based network The network is segmented into subnetworks to prevent unauthorised access segmentation t Data encryption Transmitted data (bus-payload link) is encrypted

oi

Malware Protection Mission operated systems employ malicious code protection mechanisms to

xpl

e detect and eradicate malicious code es Vulnerability Management Vulnerability management processes and procedures are defined and

ti

ili implemented ab Installation of software on Procedures for software installation on operational systems are defined and operational systems implemented

lner

vu Vulnerability scanning Vulnerability scanning is used to identify vulnerabilities

d n

a Security Testing Results Results of penetration testing, and vulnerability scanning are used to build

re

report and vulnerability repositories twa Software Updates Regular software updates are performed to mitigate exploitation risk

of

S Protocol Update / Refactoring Protocols are updated based on emerging threats and vulnerabilities y: Software Source Control The use of binary or machine-executable code is controlled

it iv

ct ASIC/FPGA Manufacturing Trusted hardware development is ensured /a Integrity Checking and Integrity checking mechanisms are used to verify software, firmware, and

re

Assurance information integrity twa Access rights Access control policies and procedure determining access rights to information sof and associated assets are defined and implemented

/

Software Version Numbers Version numbers of COTS or Open-Source are protected ode Software Bill of Materials The Software Bill of Materials (SBOM) is generated to identify known

c

vulnerabilities ious Outsourced development Activities related to outsourced system development are monitor and reviewed

ic

Incident Response Plan Procedures and processes for Incident Response are defined and documented

Mal

Incident Thresholds Incident thresholds are defined and documented based on an understanding of potential impact Incident Recovery Plan Procedures and processes for Incident Recovery are defined and documented Critical Services Delivery Resilience requirements to support delivery of critical services are established Requirements for all operating states Cyber threat intelligence Cyber threat intelligence is collected and analysed Dynamic Code Analysis Dynamic Code Analysis is performed to identify software/firmware weaknesses and vulnerabilities Static Code Analysis Static Code Analysis is performed to identify system-relevant weaknesses Detection Processes Detection processes are continuously improved Deception and Decoys Deception and decoys are employed for defensive capabilities Long Duration Testing Long Duration Testing is performed to identify race conditions and time-based attacks Coding Standard Secure coding principles for software development are defined and implemented to ensure proper security constructs are in place Secure Development Lifecycle Rules for the secure development of software and systems should be re established and applied.

ay

wa -D Installation of software on Procedures for software installation on operational systems are defined and

d o

operational systems implemented

har Zer t

: Security Information and Event Logs of security-relevant events are integrated into a Security Information and

of oi

re pl Management (SIEM) / Security Event Management (SIEM) system ion ex Operations Center (SOC)

at twa

ul Dynamic Code Analysis Dynamic Code Analysis is performed to identify software/firmware weaknesses

p sof

and vulnerabilities

and

Mani Static Code Analysis Static Code Analysis is performed to identify system-relevant weaknesses

55

SPACE THREAT LANDSCAPE

March 2025

Criticality Analysis Criticality analysis is performed to identify critical functions, components and data flows Secure Development Lifecycle Rules for the secure development of software and systems should be established and applied. Cybersecurity-Safe Mode Secure vehicle fault management functions and safe mode operations are implemented to enable a cyber-safe mode when threats are detected Separation of Environments The development, testing and production environments are separated and secured Cryptography & Crypto Key Rules for the use of cryptography are defined and implemented; On-board Management messages are encrypted

es

ic Power Masking Power masking is used to protect secret keys

erv

s Data Loss Prevention Data Loss Prevention (DLP) solutions and measures are employed

ing

Remote access management Remote access management procedure and processes are defined and

nt

documented

ve

re Software Supply Chain Integrity Technical measures are in place to ensure integrity of the supply chain

P

Incident Response Plan Procedures and processes for Incident Response are defined and documented Incident Recovery Plan Procedures and processes for Incident Recovery are defined and documented Critical Services Delivery Resilience requirements to support delivery of critical services are established Requirements for all operating states Criticality Analysis Criticality analysis is performed to identify critical functions, components, and data flows Access-based network The network is segmented into subnetworks to prevent unauthorised access segmentation On-board Message Encryption Encryption of the message and the space link

n

o Access control Access control policies and procedures are defined and documented

ti

Relay Protection Relay and replay-resistant authentication mechanisms and employed System redundancy & backup Redundancy is introduced for critical infrastructure and data is backed up

xhaus

Software and Hardware Testing End to end testing is performed according to documented procedures

e

Function Dynamic Code Analysis Dynamic Code Analysis is performed to identify software/firmware weaknesses

ource

and vulnerabilities

es

R Deception and Decoys Deception and decoys are employed for defensive capabilities Configuration Management Configurations, including security configurations, are defined, documented, implemented, monitored, and reviewed. Secure Development Lifecycle Rules for the secure development of software and systems should be established and applied. Cybersecurity-Safe Mode Secure vehicle fault management functions and safe mode operations are implemented to enable a cyber-safe mode when threats are detected Secure Command Mode(s) Spacecraft protection is enhanced by additional protection modes Change Management Change management procedures are defined and documented Transport Security Transport from the integration hall to the test stations, between different facilities, and to the start facility is secured Tamper Protection Physical inspection of hardware is performed to identify potential tampering Access-based network The network is segmented into subnetworks to prevent unauthorised access segmentation Data Loss Prevention Data Loss Prevention (DLP) solutions and measures are employed

l o

Real-time physics model-based Real-time physics model-based system is used to verify data input and control ontr system verification sequence changes c Protocol Update / Refactoring Protocols are updated based on emerging threats and vulnerabilities

of

zure Access control Access control policies and procedures are defined and documented

ei

S Authentication information Allocation and management of authentication information governed by a management management process, including guidance for personnel on proper handling. Access rights Access control policies and procedure determining access rights to information and associated assets are defined and implemented Remote access management Remote access management procedure and processes are defined and documented Multi factor authentication The zero-trust concept is applied to access management

Asset lifecycle management Guidelines and procedures for the asset management lifecycle are defined and documented Intrusion Detection and On-board Intrusion detection/prevention systems (IDP/IPS) are employed to Prevention detect and respond to threats and attacks

56

SPACE THREAT LANDSCAPE

March 2025

Physical Seizure Space traffic control and debris mitigation protocols are established Secure Workload-to-Workload Procedures for secure authentication integration protocol are defined and Authenticator documented

Threat modelling Threat modelling is employed to identify and reduce the attack surface Risk management Risk management processes and procedures are defined and implemented Installation of software on Procedures for software installation on operational systems are defined and operational systems implemented Access control Access control policies and procedures are defined and documented Identity management Identities are managed throughout their lifecycle Authentication information Allocation and management of authentication information governed by a management management process, including guidance for personnel on proper handling. Access rights Access control policies and procedure determining access rights to information and associated assets are defined and implemented Authentication Authentication procedures are defined and documented

ng ri

Multi factor authentication The zero-trust concept is applied to access management

inee

Insider Threat Protection Insider Threat procedures and guidelines are defined and documented

ng

Restricted zones access Informal meeting places within restricted zones are defined

l E

Password security A password policy and guidelines are defined and documented ocia Asset Inventory An asset inventory if established and maintained

S

Return of assets A procedure for asset management following termination of cooperation is defined and documented Equipment maintenance Procedures and processes for equipment maintenance are defined and implemented Continuous Personnel Personnel activity is monitored to detect anomalous behaviours Monitoring

Cybersecurity awareness and Cybersecurity is included in human resources practices and personnel are training provided with awareness and training Simulation Testing The resilience of segments is tested using attack simulations across the lifecycle Transmission security Transmission security solutions and measures are employed to protect communication transmission Cryptography & Crypto Key Rules for the use of cryptography are defined and implemented; On-board Management messages are encrypted Network and Communications Communications are monitored to identify cybersecurity events and verify the Monitoring Function effectiveness of protective measures Critical Telemetry Points Critical telemetry points are monitored for malicious activities Monitoring

ing

Space-Based Radio Frequency Space-based RF mapping is in place to monitor and analyse the RF poof Mapping environment

S

Defensive Jamming and Jammers and spoofers are employed for defensive operations Spoofing Antenna Nulling and Adaptive Antenna nulling and adaptive filtering are employed for defensive operations Filtering Third Party risk management Cyber supply chain risk management processes are defined and implemented Backdoor Commands Non-critical backdoor commands are disabled e ASIC/FPGA Manufacturing Trusted hardware development is ensured

is

m Supplier Security Management Supplier or Third-Party compliance with relevant security standards is reviewed pro Software Version Numbers Version numbers of COTS or Open-Source are protected

om

C Software Bill of Materials The Software Bill of Materials (SBOM) is generated to identify known in vulnerabilities ha Software Supply Chain Integrity Technical measures are in place to ensure integrity of the supply chain C Cloud Cybersecurity Measures SLAs are in place external services and cloud providers

ly

Outsourced development Activities related to outsourced system development are monitor and reviewed upp Information sharing Information is actively shared to achieve broader cybersecurity situational

S

awareness

57

SPACE THREAT LANDSCAPE

March 2025

Secure Workload-to-Workload Procedures for secure authentication integration protocol are defined and Authenticator documented Threat modelling Threat modelling is employed to identify and reduce the attack surface Adaptive Risk Response and Continuous process of qualitative and quantitative mission security risk Resource Allocation Function analysis and risk response is conducted for the duration of the mission Risk management Risk management processes and procedures are defined and implemented Transport Security Transport from the integration hall to the test stations, between different facilities, and to the start facility is secured Communications Security Secure communication protocols are employed to prevent unauthorized disclosure of, and detect changes to information Smart Contracts Smart contracts are used to enforce security protocols Secret Shares Secret shares are employed Power Masking Power masking is used to protect secret keys Installation of software on Procedures for software installation on operational systems are defined and operational systems implemented Computing Device Computing devices are authenticated before network connections are Authentication established

ion

Access control Access control policies and procedures are defined and documented

at

m Identity management Identities are managed throughout their lifecycle or Authentication information Allocation and management of authentication information governed by a inf management management process, including guidance for personnel on proper handling. ion Access rights Access control policies and procedure determining access rights to information at and associated assets are defined and implemented

ic

nt Authentication Authentication procedures are defined and documented he Multi factor authentication The zero-trust concept is applied to access management

ut

Insider Threat Protection Insider Threat procedures and guidelines are defined and documented

a

of Restricted zones access Informal meeting places within restricted zones are defined

t

Password security A password policy and guidelines are defined and documented Thef Asset Inventory An asset inventory if established and maintained Return of assets A procedure for asset management following termination of cooperation is defined and documented Equipment maintenance Procedures and processes for equipment maintenance are defined and implemented Network and Communications Communications are monitored to identify cybersecurity events and verify the Monitoring Function effectiveness of protective measures Intrusion Detection and On-board Intrusion detection/prevention systems (IDP/IPS) are employed to Prevention detect and respond to threats and attacks

Continuous Personnel Personnel activity is monitored to detect anomalous behaviours Monitoring Cybersecurity awareness and Cybersecurity is included in human resources practices and personnel are training provided with awareness and training OSAM Dual Authorization Multi-factor authentication is employed for OSAM servicers Simulation Testing The resilience of segments is tested using attack simulations across the lifecycle Adaptive Risk Response and Continuous process of qualitative and quantitative mission security risk Resource Allocation Function analysis and risk response is conducted for the duration of the mission Risk management Risk management processes and procedures are defined and implemented Separation of Environments The development, testing and production environments are separated and ers secured

et

Communications Security Secure communication protocols are employed to prevent unauthorized

am

disclosure of, and detect changes to information

ar

P Malware Protection Mission operated systems employ malicious code protection mechanisms to detect and eradicate malicious code

ion:

at Integrity Checking and Integrity checking mechanisms are used to verify software, firmware and ic Assurance information integrity

if

od Software Supply Chain Integrity Technical measures are in place to ensure integrity of the supply chain

m

d Cloud Cybersecurity Measures SLAs are in place external services and cloud providers se Event detection communication Event detection is communicated to stakeholders hori Anomaly detection Event data is correlated from multiple sources and communicated; Inappropriate or malicious activity within the mission’s systems is detected naut Mission Cyber Actor Actions An on-board cyber actor actions detection function is in place

U

Detection Critical Telemetry Points Critical telemetry points are monitored for malicious activities Monitoring

58

SPACE THREAT LANDSCAPE

March 2025

Reinforcement Learning A reinforcement learning agent is deployed to detect anomalous events Space-Based Radio Frequency Space-based RF mapping is in place to monitor and analyse the RF Mapping environment Continuous Personnel Personnel activity is monitored to detect anomalous behaviours Monitoring Dependency Confusion Protections are in place for mitigating dependency confusion Software Mission Assurance Assurance activities are performed according to documented procedures Software and Hardware Testing End to end testing is performed according to documented procedures Function Dynamic Code Analysis Dynamic Code Analysis is performed to identify software/firmware weaknesses and vulnerabilities Static Code Analysis Static Code Analysis is performed to identify system-relevant weaknesses Machine Learning Data Integrity Data integrity testing is performed on AI/ML training datasets OSAM Dual Authorization Multi-factor authentication is employed for OSAM servicers Simulation Testing The resilience of segments is tested using attack simulations across the lifecycle Detection processes are tested Event detection processes are tested to ensure they are operating as intended Detection Processes Detection processes are continuously improved Secure Workload-to-Workload Procedures for secure authentication integration protocol are defined and Authenticator documented Threat modelling Threat modelling is employed to identify and reduce the attack surface Risk management Risk management processes and procedures are defined and implemented Transport Security Transport from the integration hall to the test stations, between different facilities, and to the start facility is secured Installation of software on Procedures for software installation on operational systems are defined and operational systems implemented Computing Device Computing devices are authenticated before network connections are Authentication established Access control Access control policies and procedures are defined and documented Identity management Identities are managed throughout their lifecycle ent Authentication information Allocation and management of authentication information governed by a

m

ip management management process, including guidance for personnel on proper handling. qu Access rights Access control policies and procedure determining access rights to information e and associated assets are defined and implemented

of

Authentication Authentication procedures are defined and documented use Multi factor authentication The zero-trust concept is applied to access management

d

Insider Threat Protection Insider Threat procedures and guidelines are defined and documented

se

Restricted zones access Informal meeting places within restricted zones are defined

hori

Password security A password policy and guidelines are defined and documented naut Asset Inventory An asset inventory if established and maintained U Return of assets A procedure for asset management following termination of cooperation is defined and documented Equipment maintenance Procedures and processes for equipment maintenance are defined and implemented Secure disposal or re-use of Procedures and processes for disposal/re-use of equipment are defined and equipment implemented Continuous Personnel Personnel activity is monitored to detect anomalous behaviours Monitoring Cybersecurity awareness and Cybersecurity is included in human resources practices and personnel are training provided with awareness and training Simulation Testing The resilience of segments is tested using attack simulations across the lifecycle

59

SPACE THREAT LANDSCAPE

March 2025

6.1.2. Controls for addressing threats from eavesdropping / interception / hijacking (EIH) Table 5: Controls for addressing threats from eavesdropping/interception/hijacking (EIH)

THREAT CONTROL TITLE CONTROL

Transmission security Transmission security solutions and measures are employed to protect communication transmission Resilient Position, Navigation, Authentication mechanisms to verify GNSS information sources are in place and Timing Communication Physical Alternate physical mediums for networking are in place to mitigate network Medium security concerns Traffic Flow Security Traffic flow security and confidentiality measures are in place to mitigate traffic analysis attacks Access-based network The network is segmented into subnetworks to prevent unauthorised access segmentation Cryptography & Crypto Key Rules for the use of cryptography are defined and implemented; On-board

g

n Management messages are encrypted

ki

On-board Message Encryption Encryption of the message and the space link

ac

ij Satellite Unit RF Encryption Encryption of RF link

H

Installation of software on Procedures for software installation on operational systems are defined and operational systems implemented Computing Device Computing devices are authenticated before network connections are Authentication established Network and Communications Communications are monitored to identify cybersecurity events and verify the Monitoring Function effectiveness of protective measures Software and Hardware Testing End to end testing is performed according to documented procedures Function Antenna Nulling and Adaptive Antenna nulling and adaptive filtering are employed for defensive operations Filtering Adaptive Risk Response and Continuous process of qualitative and quantitative mission security risk Resource Allocation Function analysis and risk response is conducted for the duration of the mission Risk management Risk management processes and procedures are defined and implemented Communications Security Secure communication protocols are employed to prevent unauthorized disclosure of, and detect changes to information Transmission security Transmission security solutions and measures are employed to protect on communication transmission

ti

ca Resilient Position, Navigation, Authentication mechanisms to verify GNSS information sources are in place ni and Timing

u

m Communication Physical Alternate physical mediums for networking are in place to mitigate network om Medium security concerns c Access-based network The network is segmented into subnetworks to prevent unauthorised access of segmentation ion Cryptography & Crypto Key Rules for the use of cryptography are defined and implemented; On-board ept Management messages are encrypted erc On-board Message Encryption Encryption of the message and the space link Int Satellite Unit RF Encryption Encryption of RF link Data encryption Transmitted data (bus-payload link) is encrypted Protocol Update / Refactoring Protocols are updated based on emerging threats and vulnerabilities Session Termination Procedures for session termination are established Network and Communications Communications are monitored to identify cybersecurity events and verify the Monitoring Function effectiveness of protective measures

60

SPACE THREAT LANDSCAPE

March 2025

Adaptive Risk Response and Continuous process of qualitative and quantitative mission security risk Resource Allocation Function analysis and risk response is conducted for the duration of the mission

Risk management Risk management processes and procedures are defined and implemented Communications Security Secure communication protocols are employed to prevent unauthorized disclosure of, and detect changes to information Transmission security Transmission security solutions and measures are employed to protect communication transmission Resilient Position, Navigation, Authentication mechanisms to verify GNSS information sources are in place

le

and Timing

idd

Communication Physical Alternate physical mediums for networking are in place to mitigate network

-M

he Medium security concerns

-t

Cryptography & Crypto Key Rules for the use of cryptography are defined and implemented; On-board

-in

Management messages are encrypted Man On-board Message Encryption Encryption of the message and the space link Satellite Unit RF Encryption Encryption of RF link Data encryption Transmitted data (bus-payload link) is encrypted Session Termination Procedures for session termination are established Network and Communications Communications are monitored to identify cybersecurity events and verify the Monitoring Function effectiveness of protective measures

Critical Telemetry Points Critical telemetry points are monitored for malicious activities Monitoring Adaptive Risk Response and Continuous process of qualitative and quantitative mission security risk Resource Allocation Function analysis and risk response is conducted for the duration of the mission

Risk management Risk management processes and procedures are defined and implemented n Communications Security Secure communication protocols are employed to prevent unauthorized

o

ti nk) disclosure of, and detect changes to information

la

Li Access-based network The network is segmented into subnetworks to prevent unauthorised access

ipu

segmentation

an load

Cryptography & Crypto Key Rules for the use of cryptography are defined and implemented; On-board

m ay

-P Management messages are encrypted work us On-board Message Encryption Encryption of the message and the space link et (B Satellite Unit RF Encryption Encryption of RF link

N

Data encryption Transmitted data (bus-payload link) is encrypted Network and Communications Communications are monitored to identify cybersecurity events and verify the Monitoring Function effectiveness of protective measures Adaptive Risk Response and Continuous process of qualitative and quantitative mission security risk Resource Allocation Function analysis and risk response is conducted for the duration of the mission Risk management Risk management processes and procedures are defined and implemented Communications Security Secure communication protocols are employed to prevent unauthorized disclosure of, and detect changes to information Transmission security Transmission security solutions and measures are employed to protect communication transmission ) Resilient Position, Navigation, Authentication mechanisms to verify GNSS information sources are in place

C

(T and Timing Smart Contracts Smart contracts are used to enforce security protocols

ion

at Communication Physical Alternate physical mediums for networking are in place to mitigate network ul Medium security concerns

p

Access-based network The network is segmented into subnetworks to prevent unauthorised access

ani

segmentation

m

ic Cryptography & Crypto Key Rules for the use of cryptography are defined and implemented; On-board

ff

Management messages are encrypted

ra

t On-board Message Encryption Encryption of the message and the space link Satellite Unit RF Encryption Encryption of RF link

work

Protocol Update / Refactoring Protocols are updated based on emerging threats and vulnerabilities

et

N Integrity Checking and Integrity checking mechanisms are used to verify software, firmware and Assurance information integrity Network and Communications Communications are monitored to identify cybersecurity events and verify the Monitoring Function effectiveness of protective measures

Critical Telemetry Points Critical telemetry points are monitored for malicious activities Monitoring Detection Processes Detection processes are continuously improved

61

SPACE THREAT LANDSCAPE

March 2025

Adaptive Risk Response and Continuous process of qualitative and quantitative mission security risk Resource Allocation Function analysis and risk response is conducted for the duration of the mission Risk management Risk management processes and procedures are defined and implemented Communications Security Secure communication protocols are employed to prevent unauthorized disclosure of, and detect changes to information Transmission security Transmission security solutions and measures are employed to protect ) communication transmission ry Resilient Position, Navigation, Authentication mechanisms to verify GNSS information sources are in place

et

and Timing

m

le Access-based network The network is segmented into subnetworks to prevent unauthorised access

te

( segmentation on Cryptography & Crypto Key Rules for the use of cryptography are defined and implemented; On-board

ti

Management messages are encrypted

ec

On-board Message Encryption Encryption of the message and the space link

det

on Satellite Unit RF Encryption Encryption of RF link Data encryption Transmitted data (bus-payload link) is encrypted

ositi

P Protocol Update / Refactoring Protocols are updated based on emerging threats and vulnerabilities Network and Communications Communications are monitored to identify cybersecurity events and verify the Monitoring Function effectiveness of protective measures Mission Cyber Actor Actions An on-board cyber actor actions detection function is in place Detection Critical Telemetry Points Critical telemetry points are monitored for malicious activities Monitoring Adaptive Risk Response and Continuous process of qualitative and quantitative mission security risk ic Resource Allocation Function analysis and risk response is conducted for the duration of the mission

ff

ra Risk management Risk management processes and procedures are defined and implemented t Communications Security Secure communication protocols are employed to prevent unauthorized

on

ti disclosure of, and detect changes to information

ca

Transmission security Transmission security solutions and measures are employed to protect uni communication transmission

m

m Resilient Position, Navigation, Authentication mechanisms to verify GNSS information sources are in place

o

and Timing

c

ic Smart Contracts Smart contracts are used to enforce security protocols Cryptography & Crypto Key Rules for the use of cryptography are defined and implemented; On-board

hent

Management messages are encrypted

ut

a On-board Message Encryption Encryption of the message and the space link

Satellite Unit RF Encryption Encryption of RF link corded Data encryption Transmitted data (bus-payload link) is encrypted re Relay Protection Relay and replay-resistant authentication mechanisms and employed of Network and Communications Communications are monitored to identify cybersecurity events and verify the ay Monitoring Function effectiveness of protective measures epl Critical Telemetry Points Critical telemetry points are monitored for malicious activities

R

Monitoring Intellectual property rights Procedures and processes for protecting intellectual property are defined and documented Adaptive Risk Response and Continuous process of qualitative and quantitative mission security risk Resource Allocation Function analysis and risk response is conducted for the duration of the mission Risk management Risk management processes and procedures are defined and implemented Communications Security Secure communication protocols are employed to prevent unauthorized disclosure of, and detect changes to information s Transmission security Transmission security solutions and measures are employed to protect

es

communication transmission

cc

a Backdoor Commands Non-critical backdoor commands are disabled

d

Smart Contracts Smart contracts are used to enforce security protocols

se

Traffic Flow Security Traffic flow security and confidentiality measures are in place to mitigate traffic hori analysis attacks Access-based network The network is segmented into subnetworks to prevent unauthorised access

naut

U segmentation Cryptography & Crypto Key Rules for the use of cryptography are defined and implemented; On-board Management messages are encrypted On-board Message Encryption Encryption of the message and the space link Power Masking Power masking is used to protect secret keys Satellite Unit RF Encryption Encryption of RF link Data encryption Transmitted data (bus-payload link) is encrypted

62

SPACE THREAT LANDSCAPE

March 2025

Malware Protection Mission operated systems employ malicious code protection mechanisms to detect and eradicate malicious code Integrity Checking and Integrity checking mechanisms are used to verify software, firmware, and Assurance information integrity Equipment maintenance Procedures and processes for equipment maintenance are defined and implemented Software Supply Chain Integrity Technical measures are in place to ensure integrity of the supply chain Network and Communications Communications are monitored to identify cybersecurity events and verify the Monitoring Function effectiveness of protective measures Intrusion Detection and On-board Intrusion detection/prevention systems (IDP/IPS) are employed to Prevention detect and respond to threats and attacks Event detection communication Event detection is communicated to stakeholders

Anomaly detection Event data is correlated from multiple sources and communicated; Inappropriate or malicious activity within the mission’s systems is detected Mission Cyber Actor Actions An on-board cyber actor actions detection function is in place Detection Critical Telemetry Points Critical telemetry points are monitored for malicious activities Monitoring Reinforcement Learning A reinforcement learning agent is deployed to detect anomalous events Space-Based Radio Frequency Space-based RF mapping is in place to monitor and analyse the RF Mapping environment Dependency Confusion Protections are in place for mitigating dependency confusion Software Mission Assurance Assurance activities are performed according to documented procedures Software and Hardware Testing End to end testing is performed according to documented procedures Function Dynamic Code Analysis Dynamic Code Analysis is performed to identify software/firmware weaknesses and vulnerabilities Static Code Analysis Static Code Analysis is performed to identify system-relevant weaknesses Long Duration Testing Long Duration Testing is performed to identify race conditions and time-based attacks OSAM Dual Authorization Multi-factor authentication is employed for OSAM servicers Simulation Testing The resilience of segments is tested using attack simulations across the lifecycle Detection processes are tested Event detection processes are tested to ensure they are operating as intended Detection Processes Detection processes are continuously improved

6.1.3. Controls for addressing threats from physical attacks (PA) Table 6: Controls for addressing threats from physical attacks (PA)

THREAT CONTROL TITLE CONTROL

Secure Workload-to-Workload Procedures for secure authentication integration protocol are defined and Authenticator documented Threat modelling Threat modelling is employed to identify and reduce the attack surface

ion

Risk management Risk management processes and procedures are defined and implemented Access control Access control policies and procedures are defined and documented

orrupt

Access rights Access control policies and procedure determining access rights to information

c

and associated assets are defined and implemented

or

Authentication Authentication procedures are defined and documented

ion,

Insider Threat Protection Insider Threat procedures and guidelines are defined and documented

tort

Asset Inventory An asset inventory if established and maintained

ex

, Return of assets A procedure for asset management following termination of cooperation is on defined and documented

ci

Continuous Personnel Personnel activity is monitored to detect anomalous behaviours oer Monitoring

C

Cybersecurity awareness and Cybersecurity is included in human resources practices and personnel are training provided with awareness and training

63

SPACE THREAT LANDSCAPE

March 2025

Transport Security Transport from the integration hall to the test stations, between different facilities, and to the start facility is secured

of

Disable Physical Ports Physical ports are disabled prior to operations

on s

ti et Security Testing Results Results of penetration testing and vulnerability scanning are used to build ss report and vulnerability repositories

truc a

Manoeuvrability Satellite evasive manoeuvre protocols are implemented

es

D ent Deception and Decoys Deception and decoys are employed for defensive capabilities

gm Physical Seizure Space traffic control and debris mitigation protocols are established

age/ se

Defensive Dazzling/Blinding Laser systems are employed to dazzle or blind the optical or infrared sensors am of ASAT weapons.

D

Protective Technology Mechanisms to ensure resilience requirements are defined and employed Manoeuvrability Satellite evasive manoeuvre protocols are implemented

of se

on Deception and Decoys Deception and decoys are employed for defensive capabilities

ti the u a T

truc A Physical Seizure Space traffic control and debris mitigation protocols are established

vi S es e it A D ll

of Defensive Dazzling/Blinding Laser systems are employed to dazzle or blind the optical or infrared sensors

te

age/ of ASAT weapons. Protective Technology Mechanisms to ensure resilience requirements are defined and employed

am D the sa

Transport Security Transport from the integration hall to the test stations, between different g facilities, and to the start facility is secured

n ing

pp System redundancy Redundancy is introduced for critical infrastructure and data is backed up

Loss duri shi

t Anti-counterfeit Hardware Anti-counterfeit policy and procedures are defined and implemented

of ge /s

Disable Physical Ports Physical ports are disabled prior to operations

re re wa

abota through dwa Security Testing Results Results of penetration testing, and vulnerability scanning are used to build

S

har report and vulnerability repositories Transport Security Transport from the integration hall to the test stations, between different

d

facilities, and to the start facility is secured

se al ic hori phys access naut U

6.1.4. Controls for addressing threats from unintentional damage (UD) Table 7: Controls for addressing threats from unintentional damage (UD)

THREAT CONTROL TITLE CONTROL

Access-based network The network is segmented into subnetworks to prevent unauthorised access segmentation

ion of k gat

Data encryption Transmitted data (bus-payload link) is encrypted

Lac gre se

Cybersecurity-Safe Mode Secure vehicle fault management functions and safe mode operations are implemented to enable a cyber-safe mode when threats are detected rrors Critical Services Delivery Resilience requirements to support delivery of critical services are established

e

Requirements for all operating states

ng

ti Software and Hardware Testing End to end testing is performed according to documented procedures

ra

Function

Ope Detection processes are tested Event detection processes are tested to ensure they are operating as intended Configuration Management Configurations, including security configurations, are defined, documented, ion implemented, monitored, and reviewed.

re Coding Standard Secure coding principles for software development are defined and igurat implemented to ensure proper security constructs are in place

twa

of nf Secure Development Lifecycle Rules for the secure development of software and systems should be S co established and applied.

is

m Backdoor Commands Non-critical backdoor commands are disabled

64

SPACE THREAT LANDSCAPE

March 2025

Vulnerability Management Vulnerability management processes and procedures are defined and implemented Installation of software on Procedures for software installation on operational systems are defined and operational systems implemented Vulnerability scanning Vulnerability scanning is used to identify vulnerabilities Security Testing Results Results of penetration testing and vulnerability scanning are used to build report and vulnerability repositories Software Updates Regular software updates are performed to mitigate exploitation risk Protocol Update / Refactoring Protocols are updated based on emerging threats and vulnerabilities

Software Source Control The use of binary or machine-executable code is controlled ASIC/FPGA Manufacturing Trusted hardware development is ensured Integrity Checking and Integrity checking mechanisms are used to verify software, firmware, and Assurance information integrity Dynamic Code Analysis Dynamic Code Analysis is performed to identify software/firmware weaknesses and vulnerabilities Information Security Policies An Information Security Policy (ISP) and other relevant cybersecurity policies and guidelines are defined and documented (e.g. change management policy, remote access policy, incident response, and other) Information security roles and Information security roles and responsibilities are defined responsibilities Resource allocation Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies. Assessment & Authorization Assessment & Authorization (A&A) procedures and processes are defined and concept documented Business Impact Analysis (BIA) Business Impact Analysis (BIA) is conducted to identify and assess potential impacts of threats and the likelihood of their occurrence. It is crucial process for BCM that identifies and evaluates the potential effects of disruptions on critical business operations. BIA informs the BCM strategy, ensuring that roles and responsibilities are clearly defined, with teams assigned to mitigate risks

ent

m and implement effective recovery measures in the event of a disruption. Separation of Environments The development, testing and production environments are separated and secured

anage

Data Management Data is protected in all states (rest, transit, use)

m

g/ Integrity Checking and Integrity checking mechanisms are used to verify software, firmware and

n

Assurance information integrity

ni

an Asset Inventory An asset inventory if established and maintained pl Asset prioritisation Guidelines for asset prioritisation are defined

ty

Public relations management Information distribution during an incident is centralised and coordinated. curi during incidents

se

e Incident Response Plan Procedures and processes for Incident Response are defined and documented Incident Thresholds Incident thresholds are defined and documented based on an understanding of quat potential impact Incident Recovery Plan Procedures and processes for Incident Recovery are defined and documented

Inade

Critical Services Delivery Resilience requirements to support delivery of critical services are established Requirements for all operating states System redundancy Redundancy is introduced for critical infrastructure and data is backed up Software Mission Assurance Assurance activities are performed according to documented procedures Software and Hardware Testing End to end testing is performed according to documented procedures Function Long Duration Testing Long Duration Testing is performed to identify race conditions and time-based attacks Machine Learning Data Integrity Data integrity testing is performed on AI/ML training datasets Simulation Testing The resilience of segments is tested using attack simulations across the lifecycle Detection processes are tested Event detection processes are tested to ensure they are operating as intended

65

SPACE THREAT LANDSCAPE

March 2025

6.1.5. Controls for addressing threats from failures or malfunctions (FM) Table 8: Controls for addressing threats from failures or malfunctions (FM)

THREAT CONTROL TITLE CONTROL

Emergency power sources Emergency power generators and UPS systems are in place - power chain is ir available and dimensioned properly

a ing r y te of on ti wa ure suppl or Fail condi

Cloud Cybersecurity Measures SLAs are in place external services and cloud providers

d lou ture C of ruc st ure ra inf Fail

Adaptive Risk Response and Continuous process of qualitative and quantitative mission security risk Resource Allocation Function analysis and risk response is conducted for the duration of the mission

n o ti

Risk management Risk management processes and procedures are defined and implemented

ca

ni Security of Power Systems Power randomization and power consumption obfuscation techniques are

u s

m employed

om work Communications Security Secure communication protocols are employed to prevent unauthorized c disclosure of, and detect changes to information

net of

Traffic Flow Security Traffic flow security and confidentiality measures are in place to mitigate traffic ure analysis attacks

Fail Emergency power sources Emergency power generators and UPS systems are in place - power chain is available and dimensioned properly Security of Power Systems Power randomization and power consumption obfuscation techniques are

r

employed

y Emergency power sources Emergency power generators and UPS systems are in place - power chain is

powe

available and dimensioned properly

of

suppl Cabling security A secure cabling protocol is defined

ure

Capacity to ensure availability The required level of availability and capacity for the ground segment is Fail maintained and established

Transport Security Transport from the integration hall to the test stations, between different facilities, and to the start facility is secured

re

Anti-counterfeit Hardware Anti-counterfeit policy and procedures are defined and implemented

ogue dwa

R Restricted zones access Informal meeting places within restricted zones are defined

har

Software Supply Chain Integrity Technical measures are in place to ensure integrity of the supply chain

6.1.6. Controls for addressing threats from outages (OUT) Table 9: Controls for addressing threats from outages (OUT)

THREAT CONTROL TITLE CONTROL

l Continuous Personnel Personnel activity is monitored to detect anomalous behaviours Monitoring

nce onne ers abse P

Security of Power Systems Power randomization and power consumption obfuscation techniques are employed

es

Security Information and Event Logs of security-relevant events are integrated into a Security Information and

ic

Management (SIEM) / Security Event Management (SIEM) system

erv

s ure Operations Center (SOC)

il

ty Emergency power sources Emergency power generators and UPS systems are in place - power chain is

fa

uri available and dimensioned properly ec Capacity to ensure availability The required level of availability and capacity for the ground segment is

S

maintained and established

66

SPACE THREAT LANDSCAPE

March 2025

6.1.7. Controls for addressing threats from disasters (DIS) Table 10: Controls for addressing threats from disasters (DIS)

THREAT CONTROL TITLE CONTROL

Transport Security Transport from the integration hall to the test stations, between different c facilities, and to the start facility is secured

ri

ards System redundancy Redundancy is introduced for critical infrastructure and data is backed up

osphe haz tm A

Transport Security Transport from the integration hall to the test stations, between different al facilities, and to the start facility is secured

ent m ards

on System redundancy Redundancy is introduced for critical infrastructure and data is backed up

haz nvir E

6.1.8. Controls for addressing threats from legal aspects (LEG) Table 11: Controls for addressing threats from legal aspects (LEG)

THREAT CONTROL TITLE CONTROL

Legal, statutory, regulatory, and Legal, statutory, regulatory, and contractual requirements relevant to contractual requirements information security and the organization’s approach to meet these requirements are identified, documented, and kept up to date. Intellectual property rights Procedures and processes for protecting intellectual property are defined and documented Independent review of Independent review(s) of information security (auditing) are conducted information security Criticality Analysis Criticality analysis is performed to identify critical functions, components, and data flows Third Party risk management Cyber supply chain risk management processes are defined and implemented Cybersecurity-Safe Mode Secure vehicle fault management functions and safe mode operations are implemented to enable a cyber-safe mode when threats are detected Disable Physical Ports Physical ports are disabled prior to operations Access-based network The network is segmented into subnetworks to prevent unauthorised access segmentation

s

Cryptography & Crypto Key Rules for the use of cryptography are defined and implemented; On-board

ak

le Management messages are encrypted a On-board Message Encryption Encryption of the message and the space link

at

D Secret Shares Secret shares are employed Satellite Unit RF Encryption Encryption of RF link Data encryption Transmitted data (bus-payload link) is encrypted Data Loss Prevention Data Loss Prevention (DLP) solutions and measures are employed Information Lifecycle Information assets are identified and described across their lifecycle, considering all relevant processes Supplier Security Management Supplier or Third-Party compliance with relevant security standards is reviewed Intrusion Detection and On-board Intrusion detection/prevention systems (IDP/IPS) are employed to Prevention detect and respond to threats and attacks Anomaly detection Event data is correlated from multiple sources and communicated; Inappropriate or malicious activity within the mission’s systems is detected Security Information and Event Logs of security-relevant events are integrated into a Security Information and Management (SIEM) / Security Event Management (SIEM) system Operations Center (SOC) Secure Workload-to-Workload Procedures for secure authentication integration protocol are defined and Authenticator documented of ent Information Lifecycle Information assets are identified and described across their lifecycle,

m

p considering all relevant processes suse Access control Access control policies and procedures are defined and documented

Mi equi

Return of assets A procedure for asset management following termination of cooperation is defined and documented

67

SPACE THREAT LANDSCAPE

March 2025

Equipment maintenance Procedures and processes for equipment maintenance are defined and

implemented

Continuous Personnel Personnel activity is monitored to detect anomalous behaviours

Monitoring

Secure Workload-to-Workload Procedures for secure authentication integration protocol are defined and

Authenticator documented

ty

curi Anti-counterfeit Hardware Anti-counterfeit policy and procedures are defined and implemented se Disable Physical Ports Physical ports are disabled prior to operations

g n

li Access control Access control policies and procedures are defined and documented

s

Identity management Identities are managed throughout their lifecycle

ent

hand m Return of assets A procedure for asset management following termination of cooperation is

et re

defined and documented

ss

a qui Equipment maintenance Procedures and processes for equipment maintenance are defined and

of re

implemented

e

Event detection communication Event detection is communicated to stakeholders

Continuous Personnel Personnel activity is monitored to detect anomalous behaviours

igenc

Monitoring

egl

N Simulation Testing The resilience of segments is tested using attack simulations across the

lifecycle

l Continuous Personnel Personnel activity is monitored to detect anomalous behaviours

Monitoring

usa ons of ti ef R ac

Third Party risk management Cyber supply chain risk management processes are defined and implemented - ly Anti-counterfeit Hardware Anti-counterfeit policy and procedures are defined and implemented

ASIC/FPGA Manufacturing Trusted hardware development is ensured

non supp y ( )

Supplier Security Management Supplier or Third-Party compliance with relevant security standards is reviewed

art

Cloud Cybersecurity Measures SLAs are in place external services and cloud providers

P ance chain

rd li Outsourced development Activities related to outsourced system development are monitor and reviewed

p

Thi Information sharing Information is actively shared to achieve broader cybersecurity situational

com awareness

Return of assets A procedure for asset management following termination of cooperation is

s

es defined and documented

a cc or

a edi Equipment maintenance Procedures and processes for equipment maintenance are defined and d ed m implemented

se cl d

cy Secure disposal or re-use of Procedures and processes for disposal/re-use of equipment are defined and hori re equipment implemented

spose

to Asset lifecycle management Guidelines and procedures for the asset management lifecycle are defined and

di naut

U documented

6.1.9. Controls for addressing legacy infrastructure (LEI) Table 12: Controls for addressing legacy infrastructure (LEI)

THREAT CONTROL TITLE CONTROL

Asset lifecycle management Guidelines and procedures for the asset management lifecycle are defined and

documented

o n s t ion ai at nt em

ure m st Event detection communication Event detection is communicated to stakeholders

ai or Fail m sy inf

Installation of software on Procedures for software installation on operational systems are defined and

operational systems implemented

re cy

twa Asset lifecycle management Guidelines and procedures for the asset management lifecycle are defined and

Lega sof documented

68

SPACE THREAT LANDSCAPE

March 2025

7. CONCLUSIONS AND RECOMMENDATIONS

The cybersecurity threats and vulnerabilities observed for the space solutions domain (including ground-space-user-human resources segments), pose a direct risk to the availability of essential services and industries critical to our interconnected world. Therefore, implementing a comprehensive cybersecurity strategy is essential for securing satellite infrastructure, ensuring resilience, and mitigating potential threats to the integrity and functionality of the space systems. With the commercialisation of the sector, and the range of stakeholders involved in the processes of designing, assembling, testing, launching and operating satellite infrastructure, ensuring a comprehensive approach to security becomes increasingly complex and challenging. It is therefore essential to observe and discuss the key risks and challenges related to security of the space systems, as outlined below. • Supply Chain Risk: with the space sector heavily dependent on vast global supply chains, introducing potential vulnerabilities that adversaries could exploit to compromise critical systems, is an increasing risk. The risk of supply chain intrusion is two pronged: software components are vulnerable to insertion, modification, or removal of information, and corruption of the code or functionality during development, upgrade, or update of the system; hardware components are susceptible to intentional or unintentional introduction of components or electronic chips containing defects, malware, or backdoors for system sabotage or espionage. • Use of Commercial Off-The-Shelf (COTS) components: in line with supply chain risks, space systems increasingly rely on off-the-shelf components for communication, launch, data reception, and control facilities. This poses as a challenge as details of some of these components are publicly available in open-source materials, which could be used by malicious actors to familiarise themselves with the targeted infrastructure. Additional hardening of COTS, as well as strict procedures for security cryptographic keys, are critical for safeguarding space systems. • Legacy Systems: given the nature and the location of the space systems, many space-based assets have been designed without the security considerations needed to foresee or mitigate some of the present-day cyber challenges. Their remote nature adds another layer of complexity, making necessary updates difficult and in some instances impossible, leaving vulnerabilities that render satellite systems susceptible to cyberattacks. • Limited Visibility: the remote nature of the space systems poses challenges in detecting and responding to cybersecurity incidents and addressing vulnerabilities. In contrast to legacy systems, modern satellites require regular updates through remote access, which creates another layer of risk for intrusion into the system. • Cryptographic Mechanism: depending on the nature of the space system and communication infrastructure and protocols employed, there is a high potential for interception. This is particularly the case for systems relying on radio frequency signals, which may lack encryption or use a low-grade one, heightening the risk of unauthorised access and collection of transmitted information.

69

SPACE THREAT LANDSCAPE

March 2025

• Human Error: with space systems having a high degree of human interaction, there are increased risks of unintentional data leaks, system misconfigurations, and insider threats. • Sophisticated Cyber Attacks: with space systems serving an interconnected web of services and industries, there is an increased risk of nation-state actors and APT groups, which may attempt to gain unauthorized access and exfiltrate data or disrupt critical systems. Although threats and potential impact of risk materialisation will differ depending on the satellite’s make and mission, the space threat landscape provides a baseline for considering common challenges in the space domain, to be further tailored to the given context. The recommendations listed below provide a starting point for addressing these and are widely applicable to stakeholders concerned with the cybersecurity threats related to commercial satellites and space-based technologies. • Information sharing and reporting: timely awareness of the vulnerabilities, threats and threat actors’ tactics, techniques, and procedures supports building resilience and enables space and relevant telecom operators to introduce adequate mitigation measures in a proactive manner. Information sharing with industrial peers, competent authorities and via relevant bodies (e.g. ISACs) is a prerequisite for situational awareness and knowledge sharing. Incident reporting is also an obligation of space and relevant telecom operators defined by the NIS2 Directive. • Security by default and by design: the space and satellite technical community, as well as broader space industry players, should enforce risk-based, cybersecurityinformed engineering principles. Appropriately applied, these principles will help mitigate supply chain risks, as well as security challenges associated with the use of COTS. Finally, ensuring systems and networks are designed in adherence with security by default and by design principles, the risk of weak configuration will be reduced. The rising number of initiatives aimed at standardisation of space system cybersecurity, including also non-technical measures, will provide a useful blueprint to this end. • Ensuring robust supply chain security: the NIS2 Directive will require space organisations to prioritise supply chain security and implement stricter controls throughout the supply chain lifecycle. Vetting, monitoring, and sourcing from trusted suppliers, applying diversification of the supply chains, as well as identifying counterfeit, fraudulent, and malicious equipment, are focal points for safeguarding against potential threats and effectively mitigating supply chain risks. Similar to the security by default and by design, supply chain security principles need to be cascaded down and adopted by the space and satellite technical community, as well as broader space industry players. • Analysis and testing before introducing components into the production environment: the use of COTS in commercial space systems necessitates rigorous security analysis to be conducted by stakeholders in the space and satellite technical community, as well as broader space industry players involved in development, manufacturing, or testing of satellite systems. This includes, among other, black box testing mechanisms such as fuzzing, boundary value analysis, and equivalence partitioning. The same principles should be applied to the introduction of hardware and software procured through third parties (i.e. the supply chain)

70

SPACE THREAT LANDSCAPE

March 2025

Satellite industry players as well as the broader space and satellite technical community can rely on the knowledge and practice already present amongst the cybersecurity, academia and research communities and build on lessons learnt in other critical domains for the following: • Cryptographic mechanism: space systems require deployment of effective, validated, and tested encryption measures designed to ensure security against current and anticipated threats throughout the entire mission lifecycle. Disruptive and emerging technologies, such as quantum computing, must be considered when selecting encryption protocols, to reduce the risks stemming from weak configuration and address the challenge of lack of encryption. o Future deployment of Quantum Key Distribution (QKD) via satellites will require additional robustness and availability of reliable alternative methods for communication. In the context of cryptographic technologies, a combination of quantum-resistant asymmetric cryptographic implementations (PQC) and pre-quantum asymmetric cryptographic solutions will need to be considered (hybrid), with the use of Field Programmable Gate Arrays (FPGAs) to allow reconfiguring encryption algorithms. Therefore, ensuring crypto agility will be critical, enabling systems to adapt to new cryptographic standards as they evolve, while maintaining security in the face of advancements in quantum computing. Regardless of the level of QKD maturity, Digital Signatures will still be required. • Segmentation: establishing robust segmentation measures is crucial for space systems, as it enables compartmentalising sensitive components and data. This addresses the risk of weak configuration, preventing a breach in one area to compromise the entire satellite system, ensuring strengthening resilience against different cyber threats. • Patching: regular and timely patching is essential for addressing vulnerabilities in space systems. Despite the challenges of limited visibility and the presence of legacies in satellite systems, ensuring that software and system is up to date with the latest security patches that are available closes potential entry points that could be exploited by different adversaries. • Hardening: hardening measures involve strengthening the security posture of space systems by reducing their attack surface. This is important for addressing the challenges related to the use of COTS, and includes disabling unnecessary services, implementing strict access controls, and configuring systems to minimise potential points of vulnerability. • Zero trust: Adopting a zero trust security model developed on the basis of assuming a breach, will address multiple risks across a satellite’s lifecycle. This implies a multilayered approach to access control, with access granted via continuous verification of users, devices, applications and services, and on a need-to-know basis. • Adoption of appropriate cybersecurity hygiene practices: embracing effective cybersecurity hygiene practices involves enhancing capacity through awarenessbuilding initiatives. Applicable to all stakeholders involved in the space domain, empowering the human segment of the satellite ecosystem will contribute to a reduction of risks stemming from human error.

71

SPACE THREAT LANDSCAPE

March 2025

Ultimately, as the space sector is a rapidly developing field, regulatory approaches should be designed to protect public interests without hindering performance and innovation. A risk-based approach is recommended, where oversight of risks with the greatest potential of harm are prioritised.

72

SPACE THREAT LANDSCAPE

March 2025

ANNEX A - LIST OF ACRONYMS AND ABBREVIATIONS

ACRONYMS DESCRIPTION

ADCS Attitude Determination and Control System AOCS Attitude and Orbit Control System APT Advance Persistent Threat BCM Business Continuity Management BIA Business Impact Analysis BSI German Federal Office for Information Security CCSDS Consultative Committee for Space Data Systems CDHS Command and Data Handling System CIA Confidentiality, Integrity, and Availability COM Communications Module COTS Commercial Off-The-Shelf CRA Cyber Resilience Act DIS Disaster DLP Data Loss Prevention ECSS European Cooperation for Space Standardization EGSE Electrical Ground Support Equipment EIH Eavesdropping/Interception/ Hijacking ENISA The European Union Agency for Cybersecurity EPS Electric Power Supply ERP Enterprise Resource Planning ESA European Space Agency EU European Union EU Space ISAC EU Space Information Sharing and Analysis Centre EUSPA European Union Agency for the Space Programme FM Failures or malfunctions FPGA Field Programmable Gate Array GSaaS Ground Stations as a Service GSI Geographic Information Systems GNSS Global Navigation Satellite System GPS Global Positioning System IEEE Institute of Electrical and Electronics Engineers IoT Internet of Things JAXA Japan Aerospace Exploration Agency LEG Legal LEI Legacy infrastructure MGSE Mechanical Ground Support Equipment NAA Nefarious Activity/Abuse

73

SPACE THREAT LANDSCAPE

March 2025

NASA National Aeronautics and Space Administration NIST National Institute of Standards and Technology OBC On-board Controller OBSW On-board Software OSI Open Systems Intercommunication OUT Outages PA Physical Attacks PDHS Payload Data Handling System PESTLE Political, Economic, Social, Technological, Legal and Environmental PLCOM Payload Communication Module PNT Positioning, Navigation, and Timing PQC Quantum-resistant Asymmetric Cryptographic Implementations PKI Public Key Infrastructure QKD Quantum Key Distribution RF Radio Frequency RTOS Real-Time Operating System SDG Sustainable Development Goals SDL Space Data Link SDLS CCSDS’ Space Data Link Security protocol SIEM Security information and event management SLE Space Link Extension SPARTA Aerospace Corporation’s Space Attack Research &Tactic Analysis SOC Satellite Operations Centre SPD-5 Space Policy Directive - 5 TC Telecommand TL Threat Landscape TM Telemetry TTC Telemetry, Tracking, and Command TTPs Tactics, Techniques, and Procedures UD Unintentional Damage UDHS Untrusted Data Handling System UNOOSA United Nations Office for outer Space Affairs VSAT Very Small Aperture Terminal

74

SPACE THREAT LANDSCAPE

March 2025

ANNEX B – DETAILED ASSET TAXONOMY

The four tables below provide detailed information on assets. Instances where the asset subdomain is self-explanatory and has not been broken down further into asset groups to maintain clarity and avoid repetition. Given the scope and complexity of satellite solutions and purposes, the taxonomy provides a common view of satellite assets aimed at wide applicability across the commercial satellite domain. Although not completely technology agnostic, it aims for providing a common baseline which can be tailored further, depending on mission-specific requirements. Table 13: Detailed Asset Taxonomy - Ground Segment

GROUND SEGMENT

Asset subdomain Lifecycle Category Asset subdomain Asset group Asset group description description Phase

A document and configuration Document management system that Management incl. ensures efficient collaboration, Configuration 1, 2 while controlling access to critical Management design and configuration System information. Methods and processes Design, utilised during the Prototyping and development, and design and development software Validating and optimising design quality assurance and assembly phases. development / and identifying cybersecurity 1, 2 Integrated Design vulnerabilities. Engineering

Enterprise Resource Managing project resources, Planning (ERP) such as budget, personnel, and 1, 2 software materials.

EGSE includes custom hardware ion and an EGSE controller based on an industrial PC with Win/Linux. It Electrical Ground includes specialised equipment EGSE 1, 2 roduct Support Equipment that can simulate and test

P

(EGSE) and Mechanical electrical systems on a specific Ground Support satellite before it is launched into Equipment (MGSE) as orbit. Assembly the IT/OT infrastructure backbone, enabling data MGSE mainly consists of exchange and mechanical support devices and supporting simulators features electronic and, in certain and satellite/mission cases, network controls (e.g. MGSE 1, 2 control centres. trolley, cranes with networked controls). It encompasses tools used for moving satellite hardware.

Systems partly based on Win/Linux, possibly Manufacturing supplemented by 2 Systems proprietary and open process control technology/commercial

75

SPACE THREAT LANDSCAPE

March 2025

off-the-shelf components and subsystems.

Test tools are Soft/Hardware networkable 3 Test Tools oscilloscopes or digital mustimeters

Flight dynamics software for performing orbit related computations for estimation, optimisation, and analysis of orbits for Simulators 3 mission analysis and inflight operations. These are commonly commercial off-the-shelf software solutions.

Hardware consisting of a crypto unit board that holds the keys and software utilised for encryption and loading Crypto Hardware/ keys into the satellite 1, 2 Software and satellite control centre, commonly by using symmetric encryption between the ground stations and satellites.

Email servers, databases, operating Miscellaneous systems, and other 1, 2, 3 (software) solutions for day-to-day business operations.

Phones, laptops, tablets, Miscellaneous and other devices for 1, 2, 3 (endpoint devices) day-to-day business operations

Containers for transporting the satellite to its test or launch site. Software controlling mobile Transport Transport Specialised equipment rooms with air conditioning and 3, 4 Containers Containers Software n such as the crypto unit alarm systems. o board is also

ti

a transported.

nsport Systems utilised for logistics management Tra Logistics and accurate Management (geolocation- and time- 3,4 System wise) delivery of the satellite infrastructure to the specified site.

The Centralised Checkout System is a software utilised for monitoring and managing h Systems utilised for satellite activity while in the premonitoring and Centralised launch, launch, and checkout Checkout systems 3, 4, 5 managing the satellite Checkout System phase. It is a key part of the Launc during launch. Mission Control System (software) which is used for managing the satellite throughout its operational lifecycle.

76

SPACE THREAT LANDSCAPE

March 2025

In the context of satellite operations, EGSE comprises various electrical components and supports software such as operating systems utilised to 2, 3, 4, 5, EGSE power specific software solutions 6, 7 while the satellite is in orbit. Once the satellite is in orbit, EGSE is also used for troubleshooting and diagnostics, software updates, health and status monitoring.

Software infrastructure utilised for Mission Control managing different operations 2, 3, 4 System and control the satellite.

Data exchanges include channels in the return link (satellite to ground) and the forward link (ground to satellite). Data Link (also The exchange of data happens 2, 3, 4, 5, known as Space 121 via antennas clustered as part of 6, 7 Link Extension) Telemetry, Tracking, and Command (TTC) ground stations and the Space Data Link protocol that extends on SLE. Satellite/mission control centres include physical Satellite/ Mission and digital infrastructure As per CCSDS standards, Control Centres utilised for managing communication between satellite satellite control centres and satellites should use symmetrical

ons

ti encryption where symmetrical ra master keys are loaded into two

crypto devices - on board the Ope Crypto Unit Ground satellite (usually Communication 4, 5, 6, 7

e

it Module housing CCSDS crypto

ll

te unit board) and in the satellite

a

S control centre. Given that this is only a recommendation, there are instances where the communication is not encrypted in the commercial satellite sector.

Connects control centres with Network (WAN) 4, 5, 6, 7 TTC ground stations.

Email servers, databases, Miscellaneous operating systems, and other 4, 5, 6, 7 (software) solutions for day-to-day business operations.

Phones, laptops, tablets, and 2, 3, 4, 5, Miscellaneous 6, 7 other devices for day-to-day (endpoint devices) business operations.

Ground stations are the Antenna is the essential asset of intermediary between the TTC ground stations. TTC the operations centres ground stations and payload data and satellites. Ground reception antenna systems Telemetry, stations transmit and frequently use radio frequency Tracking, and 2, 3, 4, 5, receive telemetry, Antenna and optical techniques; transmit Command (TTC) 6, 7 tracking, and command and receive radar and optical ground stations links between satellites subsystems for ground-based and operations centres. space surveillance; TTC, radar In TTC, telemetry stands and optical signal and data for the data received processing.

77

SPACE THREAT LANDSCAPE

March 2025

from the satellite to the With antenna as a physical asset, ground (downlink); SLE serves as an internet command stands for the protocol for a team of operators data sent from the to communicate with the satellite ground station to the through a TTC ground station. satellite (uplink); tracking Extension on SLE is SDL, which stands for the tracking of is a protocol used to transport the a satellite and distance satellite payload as well as measurement. These telemetry and command & are performed utilising Internet Data Link control. The TTC ground various antennas, and (Space Link station/antenna is used to the mentioned Space Extension (SLE)) provide instructions to the 4, 5, 6, 7 Link Extension and protocol / Space satellite, and this link is Space Data Link Data Link (SDL) considered as a Telecommand protocols. Ground protocol (TC). In turn, the satellite sends station services are back Telemetry (TM) to the increasingly provided on ground station, with details such a commercial basis as satellite’s status, errors, as (GSaaS) - including well as other metrics regarding downlink, uplink and satellite's payload (specific data storage - whereby equipment such as cameras or users only require sensors employed at the satellite endpoint devices to platform). access the service.

Connects TTC ground stations Network (WAN) 4, 5, 6, 7 with control centres.

Similar to TTC Ground station, Earth Antenna is the essential asset of

station/gateway provides the Earth stations. It provides

connectivity to the connection to and from satellite, Antenna 6 satellite. but it also provides

connection/gateway to consumer Earth station consists of endpoint devices.

an antenna that can

receive and/or transmit

signal to larger TTC ground stations, or Given the complexity of Earth Earth directly to the satellite. stations, in terms of the Station/Gateway Additionally, Earth components required to process

stations usually contain the signal, modem is a clustered

modems that asset covering several other

demodulate incoming components. Receiver & Modem 6 signals from the satellite Modem demodulates incoming into digital data and can signals from satellite into digital also modulate digital data and can also modulate data into signals suitable digital data into signals suitable for transmission over a for transmission over satellite satellite link. link.

78

SPACE THREAT LANDSCAPE

March 2025

Although frequently separate

from VSATs, routers are

connected to the modems. The Router 6 purpose of the router is to

disperse the signal to devices on

the network.

Table 14: Detailed Asset Taxonomy - Space Segment

SPACE SEGMENT

Asset subdomain Lifecycle Category Asset subdomain Asset group Asset group description description Phase

CDHS uses an On-Board

On-board controller Controller (OBC) that employs a 3, 4, 5, 6,

(OBC) computing platform, i.e. a 7

microcontroller and memory.

Executed on the OBC, the On-

Board Software (OBSW)

implements a remote-control

server, usually based on a Real-

On-board software Time Operating System (RTOS). 3, 4, 5, 6, CDHS manages the Command and (OBSW) OBSW handles TM/TC traffic, 7 satellite and controls all Data Handling while also providing data functions of the System (CDHS) storage, scheduling commands, spacecraft. performing autonomous actions,

and updating the program code.

RTOS is a critical part of satellite

infrastructure as it usually

)

s houses a watchdog timer. The Real-Time Operating 3, 4, 5, 6, bu latter monitors satellite health e System (RTOS) 7 it and can reset the relevant

ll systems, if necessary, as well as

te

a perform specific timed activities.

(S

ons

ti Depending on the satellite setup,

ra multiple antennas can be 3, 4, 5, 6, Antenna employed to receive/transmit 7 Ope information as well as different

e

it COM communicates signals (radio, optical, etc).

ll

with TTC ground

te

a stations and Satellite

S

Operations Centres via COM also houses the crypto unit SLE/SDL protocols. It board which contains a comprises an antenna, a symmetrical master key for radio, and potentially a encryption/decryption of computing setup (i.e. 3, 4, 5, 6, Communications Crypto Unit Board information from the satellite CCSDS crypto unit 7 Module (COM) control centres. It operates board) to handle based on CCSDS standards. decoding, protocol The hardware/software is implementations, and connected to CDHS. access projection. COM

is usually only dedicated

to TM/TCM traffic. COM COM utilises SLE/SDL protocols

is directly coupled with to communicate with TTC

the CDHS. Ground and Satellite Operations

Centres. Additionally, satellites 3, 4, 5, 6, Protocols also rely on Inter Satellite Link, 7

which enables communication

and pairing with other space

assets.

79

SPACE THREAT LANDSCAPE

March 2025

Satellites utilise ADCS

to determine and adjust

their attitude so that they

can point antennas Attitude towards the Earth and Attitude and Orbit The satellite utilises thrusters to Determination and 3, 4, 5, 6, solar panels at the Sun. Control System form AOCS, which is employed Control System 7 ADCS is also used for (AOCS) for minor orbit changes. (ADCS) managing the satellite's

spinning and positioning

once released from the

launch vehicle.

Solar cells mounted on the

surface of a satellite (e.g. wings

or body mounted solar arrays),

generating electric currents from 3, 4, 5, 6, Solar Panels incoming sunlight. Power is 7 regulated and routed to relevant

satellite equipment via a Power EPS is the satellite’s Conditioning and Distribution power supply which is Unit (PCDU). usually generated by

solar panels and Power supply Primary batteries contain a batteries. In case when (EPS) specified amount of usable EPS fails and the energy determined at the time of batteries fully drain, it is assembly which can only be impossible to operate discharged. Secondary batteries the satellite. can be recharged from other 3, 4, 5, 6, Batteries energy source, such as solar 7

panels or via Radioisotope

Thermoelectric Generators, and

provide the satellite with power

when the primary power (or its

source) are not available.

PDHS has a similar

purpose to CDHS, it can

receive data from the

Payload Communication

Module (PLCOM) but it

can also process data

directly from the payload

equipment (cameras,

sensors, etc.). PDHS

can perform computing Payload Data tasks and can also 3, 4, 5, 6, Handling System process untrusted 7 (PDHS) payload user data. It is load possible that PDHS and

y

a CDHS are linked, and P this is known as the bus-

e

it payload link. This link is

ll

te needed in cases where

a

S information relating to

n: bus components is

io needed to control the ut payload.

c e x E

PLCOM has a similar

ion purpose as COM in the

s

s bus category. It either

Mi receives structured

Payload payload data from the 3, 4, 5, 6, Communication COM or processes raw 7 Module (PLCOM) TCs intended for the

payload. Hence,

PLCOM has an antenna

and, optionally, a crypto

unit board.

Untrusted Data UDHS' purpose is to run unstructured code that 3, 4, 5, 6, Handling System 7 (UDHS) cannot pass through a

satellite's PDHS. It is

80

SPACE THREAT LANDSCAPE

March 2025

possible that PDHS contains a UDHS component and viceversa. UDHS has previously not been part of common satellite architecture but is increasingly used in commercial satellite operations where certain satellite services are rented out to third-party users.

Table 15: Detailed Asset Taxonomy - User Segment

USER SEGMENT

Asset Asset subdomain Lifecycle Category Asset group Asset group description subdomain description Phase

Antenna or satellite dish in the case of VSAT, is a specialised receiver or transmitter device Satellite dish / that communicates either with a 6 Antenna ground station (hub) or directly with the satellite (in case of it being the key node in the mesh Consumer VSATs act network). as a hub for end users to connect directly to the satellite or, more often, to larger ground stations which enable traffic for Given the complexity of VSAT clusters of different systems, in terms of the

s

e hubs. Alternatively, components required to process

c

a VSATs can connect the signal, modem is a clustered rf asset covering several other e among each other using Very Small components. Int a mesh network, in r Aperture Terminal Modem 6 e which case one of the (VSAT) Modem demodulates incoming VSAT acts as a hub and signals from satellite into digital facilitates connection data and can also modulate onsum directly to the satellite. digital data into signals suitable

C

VSATs enable other for transmission over satellite services such as GPS link. and consist of user antennas and modems for receiving and, in some cases, transmitting data. Although frequently separate from VSATs, routers are connected to the modems. The Router 6 purpose of the router is to disperse the signal to devices on the network.

81

SPACE THREAT LANDSCAPE

March 2025

User access content

exchanged via satellites

utilising endpoint

s

e devices such as satellite ic phones and laptops.

v e

Endpoint devices also

D

include satellite TV,

int

GPS receivers/devices,

and weather monitoring Endpoint devices 6 ndpo devices. Industrial

E

r systems and aircrafts

e

can also be listed within

this asset subdomain.

These assets are

onsum

C enabled through

consumer interfaces.

Table 16: Detailed Asset Taxonomy – Human Resources Segment HUMAN RESOURCES SEGMENT

Asset Asset subdomain Satellite lifecycle Satellite lifecycle actor Lifecycle Category subdomain description actors description Phase

Develop avionic features of the Aerospace engineers 1 satellite

Participate in various aspects of

satellite development Physicists 1 concerning the influence of

natural forces on the satellite.

Develop cybersecurity features Cybersecurity engineers 1 of satellite software.

Develop data infrastructure Data Engineers / 1 Scientists supporting the functioning of the

satellite.

Develop electronic and Actors participating in Electronics engineers 1 development activities electrotechnical features of the

tors

c include researchers, satellite. A Actors engineers, designers, le participating in c and scientists who Software engineers 1 y development Develop the satellite’s software.

c participate in the e activities if development of Adjust and optimise the specific

L satellites or their e Manufacturing manufacturing systems in order it supporting elements 1 ll engineers to produce satellite

te components.

a S

Develop mechanical features of Mechanical engineers 1 the satellite.

Develop the satellite’s Propulsion engineers 1 propulsion systems.

Plan and conduct testing of the Test engineers 1 satellite and its components.

Researchers / Scientists

/ Engineers concerned May participate in the

with technical fields development of various mission- 1

relevant to the nature of specific satellite features.

specific satellites

Astronomers Supply other lifecycle actors 1, 7

with expertise on influence of

82

SPACE THREAT LANDSCAPE

March 2025

Actors Actors participating in celestial bodies and forces on participating in supporting tasks the satellite, its functioning and supporting include support operations activities technicians engaged in the physical Support other actors with construction and expertise on atmospheric forces assembly of satellites Atmospheric scientists 1, 6, 7 and their influence on the or satellite components satellite and its operations. as well as the maintenance of these Analyses various data relevant during all phases of the Data analysts to the satellite operations and 6 lifecycle. This also support other actors. includes support scientific personnel, whose expertise on Manufacturing Participate in the manufacturing 2 various scientific areas, technicians of the satellite components. such as weather, atmospheric conditions Install, inspect and maintain the or specific systems is Mechanical technicians mechanical components of the 2 needed during some satellite during its assembly. phases of the satellite lifecycle, such as Install, inspect and maintain the development, launch or avionic components of the operations. satellite during its assembly, Aerospace technicians 2 and conduct on-site control of satellite avionic features prior to its launch.

Install, inspect and maintain the Electronics technicians electronic components of the 2 satellite during its assembly.

Conduct tests of the satellites or Test technicians 3 their features.

Conduct the launch related Launch technicians 4 tasks on-site.

Mange on-site testing and last check of the satellite and its Launch engineers 3 components immediately before its launch.

Manges the overall process of the satellite launch: receives reports of other relevant actors, Launch director 3, 4, 5 authorizes the process and directs the relevant actors during the process.

Manages and enforces the Operations safety safety of satellite launch 3, 4, 5, 6 manager operations.

Evaluate the weather conditions during the launch and assess Atmospheric scientists 3 the feasibility of the satellite launch.

Plan the navigational patch of GIS Analysts the satellite or its carrier during 3 launch.

Conduct tasks related to transportation of satellite or its Logistics and support components on the launch site 3, 6 staff and supports other satellite actors during the launch.

May participate in the Technicians concerned 2, 3, 4, 5 installation, inspection and with technical fields maintenance of various mission-

83

SPACE THREAT LANDSCAPE

March 2025

relevant to the nature of specific satellite features

specific satellites (robotics, laser technology etc.).

Remotely operate a satellite

SOC operators from the Satellite Operations 4, 5, 6, 7

Centre.

Manages operations of the SOC leader 4, 5, 6, 7 Satellite Operations Centre

Utilises data from GIS in

GIS analysts planning of the satellite’s 6, 7

mission and operations. Actors participating in

satellite operations

include actors who are Establish, adjust, and maintain Communication directly engaged in the the communication links 6 Actors engineers operations phase, once between satellite segments. participating in satellites are deployed satellite in orbit. Their tasks Plan a satellite mission with the operations Mission planners 6 include monitoring of assistance of other actors.

satellite functions and

management of Operate the payload, based on mission-related tasks. Payload operators the specific nature of the 6

satellite’s mission

Ground station Operate and maintain the 6 operators ground stations

Specialists concerned May participate in satellite’s with technical fields operations, based on its specific 6, 7 relevant to nature of technical features. specific satellites

84

SPACE THREAT LANDSCAPE

March 2025

ANNEX C – SPACE THREAT TAXONOMY

The eight tables below provide detailed information on threats, impact on CIA triad, and assets that are most likely to be affected by that particular threat. Table 17: Detailed Threat Taxonomy

THREAT THREAT THREAT DESCRIPTION CIA AFFECTED ASSETS CATEGORY

Ground: Production Document Management which includes Configuration Management System Prototyping and software Use of previously leaked data and development / Integrated information for malicious purposes. Design Engineering & Abuse of leaked Examples may include use of leaked C Enterprise Resource Planning (ERP) software & data credentials for launching subsequent miscellaneous software) phishing attacks or gaining unauthorised Email servers, databases, access using these. operating systems, and other solutions for day-to-day business operations. Phones, laptops, tablets, and other devices for day-to-day business operations

Ground: Design, development Misuse or modification of access rights and and quality assurance permissions to IT systems may see Assembly Manufacturing adversaries gain access to these systems, Systems after which they could be able to affect Miscellaneous (software) Miscellaneous (endpoint Abuse/ multitude of processes in any segment of CIA devices) Falsification of the satellite lifecycle. The adversaries may Logistics Management System rights affect those processes to collect Checkout systems information, change them or incapacitate Mission Control System them. This threat is frequently materialised Network (WAN) via malicious insiders trading credentials for User: monetary rewards. Consumer endpoint devices

Compromising Exfiltration of sensitive satellite data, confidential resulting in a data breach. Exfiltration can Ground: SLE/SDL protocols C ) information (data be conducted over alternative protocols User: endpoint interfaces and breaches): and web services, including also automated devices (NAA Exfiltration exfiltration.

e

s DoS can pose a threat to both the satellite bu control centre and TTC ground stations, as

a

/ well as the bus and payload of the in the y Ground: all assets it space segment, affecting their availability. Space: all assets tiv Denial of Service Given the common practice of segregation A c User: Consumer Interfaces a (DoS) between the bus and the payload, in the s devices case of the space segment, such threats riou would primarily need to be executed through the bus. DoS may be perpetrated Nefa through various kinds of techniques, such

85

SPACE THREAT LANDSCAPE

March 2025

as flooding of satellite with requests/commands, Ground: Production Document Management which includes Configuration Management System Prototyping and software development / Integrated Although a threat manifestation element of Design Engineering & several threat clusters, modification of data Enterprise Resource Planning as a threat category refers to the potential CI Data modification (ERP) software & for adversaries to modify registers, system miscellaneous software and authentication processes, and/or cloud Email servers, databases, compute infrastructure, operating systems, and other solutions for day-to-day business operations. Phones, laptops, tablets, and other devices for day-to-day business operations Analog interference with electromagnetic signals that are used for controlling heaters and flow valves of the propulsion Electromagnetic IA subsystem. Attacks aimed at these signals Space: EPS, RTOS and AOCS interference could cause freezing of propellant lines, valves locking, lead to unstable spinning of the satellite or put it in de-orbit. Threats against firmware include the potential of adversaries overwriting or Firmware A Ground: all assets corrupting firmware devices (e.g. flash corruption Space: all assets memory contents of system OS) making them inoperable or unable to boot. Targeted take-over of an identity of certain satellite lifecycle actors, by acquiring their personal items, information or other artifacts which would allow adversaries to pose as those actors. This may grant CIA Identity Theft Human resources: all assets adversaries access to processes, information or even facilities where they could perpetrate multitude of actions whose results can compromise each aspect of CIA triad of satellite lifecycle. Overpowering the frequency of a legitimate RF signal in order to disrupt communications between the ground station and the satellite, or vice versa. Jamming can result in unauthorised Ground: TTC Ground commands for guidance and control being (Antenna) A Jamming sent to the satellite, injection of malicious Space: BUS (COM) & Payload code, and/or overall Denial of Service. It is (PLCOM) one of the most common threats to space User: VSAT infrastructure targeting both ground and space segments as well as space-link communication and has been increasingly employed by a wide range of threat actors. Exploitation of weak communications protocols, commonly due to a lack of Ground: Crypto Malicious code/ encryption, or malicious use of Hardware/Software & Transport software/activity: compromised master keys or any C Container (Crypto Unit Board) & Cryptographic encryption key. This threat may result in Satellite Control Centre (Crypto exploit adversary gaining access to any Unit Ground) communication/information in the satellite Space: Crypto Unit Board lifecycle.

86

SPACE THREAT LANDSCAPE

March 2025

Injection of malicious software (e.g. Ground: Production rootkits, bootkits, backdoors) into space (Manufacturing systems & operations control systems and/or satellite Simulators & Crypto data receivers and transmitters. Malicious Malicious code/ hardware/software) & code could also be injected into software I A software/activity: Centralised Checkout Systems updates, affecting for example on-orbit Malicious injection & Satellite Operations Centre software updates, upgrades, patches, or (Mission Control System) direct memory writes. Malicious injection Space: BUS (CDHS/COM/) & could enable satellite data extraction and/or Payload (PDHS/PLCOM) manipulation targeting the bus or payload.

Exploitation of misconfigurations and

software vulnerabilities to gain Ground: Satellite Control

unauthorized access to critical systems and Centre & Centralised Checkout

Malicious code/ networks. Exploitation of the computer Systems & TTC Ground A software/activity: network (CNE) in ground control stations as (Antenna)

Network exploit a result of poor configuration could, for Space: BUS (CDHS, COM) &

example, lead to unauthorised access to Payload (PDHS, PLCOM)

and hence compromise of satellite lifecycle User: VSAT

assets.

Exploitation of security weaknesses in

satellite infrastructure resulting from poor

configuration and/or logic or

implementation errors. These may result in

systemic vulnerabilities and affect the Ground: Production satellites’ reliability and overall stability. (Manufacturing systems & Malicious code/ Threat actors may exploit such Simulators) & Centralised software/activity: weaknesses by injecting instructions to C I Checkout Systems & Satellite Software and manipulate control functions, cause Operations Centre (Mission vulnerabilities' resource exhaustion or introduce flaws in Control System) exploit satellite components via the supply chain, Space: Satellite Bus, Satellite enabling them to launch subsequent payload attacks. This threat may encompass time

synchronization executions, compromise of

boot memory, exploiting faults in

geofencing, software defined assets and

others.

Exploitation of software vulnerabilities that

are at the time of the exploitation unknown

to the user. Presenting the so-called

"unknown unknown" phenomenon, the

Zero-Day exploits are especially

threatening, since the users are not aware

Manipulation of of the fact that they should be remediating Ground: all assets hardware and them. Because of the exploitation window, CIA Space: all assets software: Zero- limited detection and response, and User: all assets Day exploit significant risk and impact, zero-day

vulnerabilities are treated with heightened

urgency and specialized approaches in

cybersecurity compared to regular software

exploits. The Zero-Day exploit may be

present in any segment of the satellite

lifecycle.

Intentional deactivation of security

safeguards such as firewalls, virus scans,

log monitoring, etc. This may manifest as a Ground: Production (Design, modification of the internal values of the Preventing CIA development, and quality satellite lifecycle assets and may include services assurance & Assembly) & modification of internal tables, registers, Satellite Control Centre algorithms, cryptographic standards and

other software components, as well as

inhibiting system recovery.

87

SPACE THREAT LANDSCAPE

March 2025

Threats of resource exhaustion affect the space segment and can be targeted both at the satellite bus and payload (incl. overall satellite operations, logical storage, and Space: BUS (CDHS/COM) & communications). In the case of satellite Payload (PLCOM/PDHS) operations, components such as the satellite ops; Resource payload receive commands to sense, emit, A BUS (CDHS, OBSW) - logical exhaustion or run whatever mission the satellite has storage; constantly, to the point that the battery is BUS (COM, antenna) fully drained/depleted. In the case of logical communications storage, this includes utilisation of storage capacity until the full limit is reached. Finally, communications are affected by the amount of traffic sent. Threats to the availability of the satellite bus as a result of adversaries taking control of space assets by exploiting existing vulnerabilities. Such hostile takeovers can Ground: TTC Ground Seizure of control: A result in overtaking control of the (SLE/SDL protocol) Satellite bus management segment to execute malicious Space: BUS (CDHS/COM) commands, as well as complete lockout of legitimate satellite users by overtaking access control. Deliberate deception regarding the identity and intention of the perpetrator in order to manipulate the victim to perform specific Ground: Design, development, actions that the adversary wants them to and quality assurance & do. The threat is mainly materialised CIA Social Engineering Satellite Control Centre & through the launch of phishing or spear Miscellaneous phishing. This way, all segments of the Software/Hardware satellite lifecycle can be affected, since the adversary can achieve anything from gathering sensitive information. Also known as "malicious misdirection". Threats aimed at deceiving the receiver, seeing adversaries transmitting erroneous data for malicious purposes via what appears to be a legitimate signal. Attacks Ground: TTC Ground involving spoofing can be launched on A I (Antenna, SLE/SDL protocol) Spoofing sensor data and/or guidance control, that Space: BUS (COM) is, on both the receiver and the transmitter User: VSAT end. Spoofing threats can result in malicious commands being sent to the satellite or erroneous data to the ground stations. Threats to and from the supply chain including potential leaks of software/tools/data sheets, malicious use Ground: Production of open-source materials on satellite (Manufacturing systems & components provided by third parties, the Assembly & Simulators) & Supply Chain use of common components in satellites CIA Centralised Checkout Systems Compromise running different missions, as well as the & Satellite Operations Centre potential of introducing malicious software (Mission Control System) & or backdoors through third parties' TTC Ground components. These threats often Space: all assets materialize from the compromise of suppliers' facilities/sites. Threats of physical or logical theft (e.g. via Ground: Crypto Theft of keylogger) with potential impact on assets Hardware/Software & Transport CIA authentication that are connected to the crypto unit board Container (Crypto Unit Board) & information or the crypto unit ground. Such threats can Satellite Control Centre (Crypto materialise in different phases of a Unit Ground) & Satellite Control

88

SPACE THREAT LANDSCAPE

March 2025

satellite's lifecycle, including while the Centre (Mission Control satellite is manufactured, being transported System) to its launch site, or via attacks on the Space: BUS (COM, Crypto Unit satellite control centre once the satellite is Board) in orbit. Deliberate or incorrect modification of a satellite's parameters or test procedures Unauthorised which could enable further tampering with CIA modification: Space: CDHS (RTOS) satellite reset and update procedures and Parameters result in infinite restarts of the satellite (manipulating RTOS components). Unauthorised access to physical devices in scope of the satellite lifecycle, such as physical workstations, machinery in Ground: Production Unauthorised use production/assembly facilities or launch CIA (Manufacturing & Assembly) & of equipment facility, may allow the adversary to conduct Satellite Control Centre (group: multitude of nefarious activities with far EGSE/MGSE) reaching consequences for the satellite lifecycle. Malicious alteration or complete replacement of a satellite's legitimate signals with the aim to reuse it for another purpose. Hijacking and unauthorised Ground: Satellite Control commands to guidance control are a threat Centre & TTC Ground I A Hijacking to both ground and space segments, (SLE/SDL protocol) primarily impacting the satellite control Space: BUS (CDHS & COM) & centre and TTC ground stations, as well as Payload (PDHS & PLCOM) the satellite bus in the space segment. This type of threats can be materialised by compromising the SLE and SDL protocols. Interception of data over a communication channel. This may concern any existing communication link in the satellite lifecycle, inside of specific segments - ground, space, user and human resources - as well Ground: TTC Ground as between the segments. It concerns both (Antenna, SLE/SDL protocol) Interception of primary and secondary communication C Space: BUS (COM) & Payload communication channels (e.g. used as backup). This threat (PLCOM) is commonly employed for cyber User: VSAT espionage, as it may compromise any information in the satellite lifecycle. For example, the threat of interception of communication can manifest itself as interception of Multi-Factor Authentication. Threats stemming from Man-in-the-Middle attacks can be materialised by bypassing

)

access control on the COM/PLCOM parts (EIH of the satellite, as well as SLE protocol on Ground: Satellite Control

g

in the ground segment. Similar to DoS, Man- Centre & TTC Ground k CIA c Man-in-the-Middle in-the-Middle attacks target the same group (SLE/SDL protocol)

a

ij of assets satellite control centres and TTC Space: BUS & Payload

H

/ ground stations in the ground segment, as User: VSAT ion well as the bus and payload in the satellite

pt

e segment. Additionally, this type of threat rc can impact VSAT in the user segment.

e

nt Threats to the link between connected

I /

payload components, in instances where

ing

Network more than one PDHS or UDHS exists (i.e. Space: BUS (CDHS & COM) & C I manipulation (Bus- denial of the link’s availability by one to the Payload (PLCOM & PHDS &

dropp

s Payload Link) others). The materialisation of such threat UDHS)

e

v may result in compromise of multiple

a

E services hosted by the satellite. This may

89

SPACE THREAT LANDSCAPE

March 2025

potentially lead to payload data leaks from

all hosted payload components.

Threats targeting the ability of a satellite to Ground: Satellite Control handle traffic coming from the ground Network traffic A Centre & TTC Ground (Antenna station (telecommand) through TC manipulation (TC) & SLE/SDL protocol) suppression. This type of threats can Space: BUS (COM) impact SLE and SDL protocols.

Adversaries obtaining information on the Ground & Space: SLE/SDL orientation of the satellite enabling them to Position detection C protocols draw conclusions on its function/mission, (telemetry) Space: CDHS (OBSW, OBC) / orbit, etc. and possibly launch subsequent ADCS (group: AOCS) targeted attacks.

Replay of previous legitimate messages

Replay of (communication traffic) at a later time to

recorded authentic trigger a system response or to enable C I Ground & Space: SLE / SDL

communication access to data. An examples of replay protocols

traffic attacks may include attacking the

scheduling table to affect tasking.

Threat actors gaining and maintaining

unauthorised access to a network, which

enables them to pre-position themselves

for reconnaissance, espionage and/or

launch of potential subsequent attacks. The

threat can be materialised via web page

Unauthorised attacks, cross-site scripting, cross-site C I Ground: all assets (including

access request forgery, drive-by hacking, phishing, SLE/SDL protocol)

or attacks on air gapped solutions (i.e.

intranet), or through brute force password

cracking. Additionally, via masquerading

techniques, threat actors presenting

themselves as legitimate entities/users can

gain unauthorised access.

The threat of violence, other harms in order

to gain access to desired premises or

information, or manipulating the victim to Coercion, extortion CIA perform other actions that the adversary Human resources: all assets or corruption wants them to do. This threat may impact

any segment of satellite lifecycle, where

human activity or interaction is present.

Intentional damage or destruction of Ground: Production & satellite infrastructure (hardware and/or Damage/ Assembly & Transport & software) as a result of intentional A Destruction of Launch & Satellite Control adversary action can negatively impact segment assets Centre & TTC Ground availability of each segment of satellite Space: all assets lifecycle.

Deliberate physical damage to the satellite

or some of its segments. This threat can

negatively impact any aspect of satellite

operations, depending on the specific

satellite asset that has been damaged.

Physical damage to the satellite can be Damage/ caused by a deliberate attack via an ASAT Destruction of the weapon. ASAT includes space or ground satellite via the A Ground: TTC Ground based directed energy weapons or kinetic use of ASAT / Space: all assets ) weapons intended to physically destroy A Proximity P satellites, namely: high-powered ( operations

s

s microwave (HPM) weapons,

e

c electromagnetic pulse (EMP), high-

c a

l powered laser weapons, laser dazzling and

a

ic blinding, and high-altitude nuclear

detonation. This also entails proximity

hys

P operations where rogue space objects

90

SPACE THREAT LANDSCAPE

March 2025

approach space assets for the purpose of

assessing their capabilities (spying),

making physical contact (ramming), or

conducting aforementioned attacks.

Any satellite lifecycle asset component may

be required to be shipped from one location

to other, for multitude of reasons, such as

calibration/verification, use, or repair. Ground: Transport Container - Loss during CIA These transfers may be both internal and Crypto Unit & Logistics shipping external to the satellite lifecycle. During the Management Systems

transfer, the asset may be lost, which would

strip any segment of the lifecycle of any

capability supplied by this asset.

Threats resulting from connection of

unauthorised rogue hardware and

software, such as USB sticks, unauthorised Ground: Design, development, applications, etc. may endanger the Sabotage through CIA and quality assurance & integrity, confidentiality and availability of hardware/software Assembly & Satellite Control satellite components. They can be Centre perpetrated as a result of intentional,

targeted human intervention or even on the

orbit itself (docking of another satellite).

Unauthorised access/intrusion into

buildings, premises and sites. This may

result into various types of threats, Unauthorised CIA including compromise, modification, Ground: all assets physical access damage to or even theft of the satellite

lifecycle assets (ground or space, if they are

located on the ground).

Although uncommon, it is possible that a

satellite does not have built-in bus-payload

segregation, or that segregation is Space: BUS (CDHS/COM) & Lack of implemented improperly. If these two asset A Payload Segregation subdomains are not segregated, potential (PDHS/PLCOM/UDHS) materialisation of threats to the satellite bus

can impact a wider set of assets, including

the satellite payload.

Improper handling of systems or

applications of satellite lifecycle assets can negatively impact each aspect of satellite CIA Operating errors Human Resources: all assets lifecycle operations. It can lead to limitation,

degradation or outright disruption of

function of these assets.

Improper configuration of software resulting

in vulnerabilities such as unsecure code Ground: Design, development, and/or logic errors. These may lead to and quality assurance & unauthorised access enabling data Manufacturing systems & Software corruption/modification (intentional or non- CIA Assembly & Simulators & misconfiguration intentional) by threat actors, and cause Satellite Control Centre further software or hardware failure, enable Ground & Space: SLE/SDL use of unauthorised software, or impact the protocols ) confidentiality, integrity or availability of

D

data.

ge (U Lack of appropriate security planning in the

a

Planning/Design phases of the lifecycle,

dam resulting in a lack of testing, for example. Space: all assets Inadequate Lack of adequate security management CIA Ground: all assets

nal

security planning / io once the satellite infrastructure is in the User: all assets nt management e operation phase may lead to unidentified or Human Resources: all assets

nt

exposed critical assets, which results in a

ni

U lack of relevant security measures due to

91

SPACE THREAT LANDSCAPE

March 2025 limited visibility of the infrastructure in its entirety.

92

SPACE THREAT LANDSCAPE

March 2025

Threat of basic services malfunctions which can result in unfavourable conditions for

people and infrastructure/systems such as Ground: Production (Design, heat or frost, due to malfunctions of air development, and quality Failure of air conditioning and water supply, etc. Apart A assurance (MGSE) & Assembly conditioning or from the production and assembly phases & Soft/Hardware Test Tools & water supply of the satellite’s lifecycle, these threats can Simulators) & Transport also impact subsequent phases if affecting Container & Launch the ground stations (e.g. server rooms

overheating due to air conditioning malfunction)

With the proliferation of Cloud solutions and

the rise of Ground Stations as a Service

(GSaaS), threats to Cloud infrastructure can deny availability of satellite receivers in

the ground segment, affecting ground Ground: Satellite Control Failure of Cloud stations as especially impacting users of A Centre & TTC Ground & VSAT

infrastructure GSaaS. This will be more pronounced with Space: BUS (CDHS) & Payload the introduction of Satellite Operations as a (PDHS, PLCOM, UDHS)

Service (SOaaS) . Furthermore, the multi-

)

tenant nature of SOaaS introduces distinct (FM threats to data privacy and service

ion availability in orbit.

Failure of communication networks may be

unct

lf caused by malfunction of either hardware of a Ground: TTC Ground Failure of software supporting this network's function m A (Antenna, SLE/SDL protocol) / communication or attack directed at them. The satellite

s

Space: BUS (COM) networks lifecycle is dependent on connectivity and ure User: VSAT so this threat may disrupt functioning of any

Fail

of its segments.

Disruption or failure of the satellite's power supply, resulting in satellite becoming Ground: Production & unresponsive due to a shut down. This can Failure of power A Assembly & Transport & happen several times as a result of, for supply Checkout systems example, faulty batteries, damage to, or Space: BUS (EPS) malfunction of other power sources, such

as solar panels, are also possible.

Tainted hardware components may be built

into both space and ground segments, ultimately resulting in hardware failure.

Failure or malfunction may occur as a result of hidden, malicious capabilities that are Ground: Assembly built in during the design and development A (EGSE/MEGSE) & Crypto Rogue hardware and assembly stages of a satellite's Hardware/Software & Satellite lifecycle. Apart from built-in malicious Control Centre

capabilities, the hardware may simply not be produced according to the specification

provided by the manufacturer, or it may be counterfeit.

Threats pertaining to limited availability of critical staff, or lack thereof, at any of the

satellite lifecycle phases. Personnel absence may result in loss/unavailability of T) Personnel C A relevant information and inability to Human Resources: all assets OU Absence ( complete tasks, comply with prescribed

s

ge roles and responsibilities, or enforce the

a

four-eyes principle for risk and quality Out assurance.

93

SPACE THREAT LANDSCAPE

March 2025

Unavailability of security safeguards such

as firewalls, virus scans, log monitoring,

etc. due to either system failure or malicious Ground: Production (Design, Security services action of an adversary. Security services CIA development, and quality

failure are key for ensuring confidentiality, integrity assurance & Manufacturing) &

and availability of satellite lifecycle Satellite Control Centre

processes, their disruption may hence

compromise each satellite lifecycle asset.

Disruption or damage of satellite

infrastructure as a result of atmospheric Ground: Simulators &

events such as electromagnetic pulses, Checkout systems (group: Atmospheric geomagnetic disturbance, or thermal A Centralised Checkout System)

hazards radiation, as well as man-made space Space: BUS (CDHS, group:

debris. Such developments can affect OBSW & RTOS; & COM; &

satellite systems both in the test ADCS, group: AOCS)

environment and in orbit.

Disruption, damage, or destruction of Ground: Design, development,

satellite infrastructure (hardware and/or and quality assurance &

software) from natural hazards such as fire, Manufacturing system &

floods, environmental pollution, dust, Assembly & Soft/Hardware Test Environmental corrosion, frost, etc. Such developments A Tools & Transport & Launch &

)

IS hazards are mainly focused on the satellite lifecycle Satellite Control Centre & TTC (D phases related to the ground and user Ground

r

te segment but can have cascading effects on Space: EPS (group: Solar

s a

links and the space segment, especially at Wings & Batteries)

is

D check-out. User: VSAT

Ground: Production

(Document Management incl. Threat of potentially disclosing sensitive Configuration Management information to external third parties or System stakeholders who do not have the need Prototyping and software and/or permission to view/access it. Leaked C development / Integrated Data leaks information can subsequently be abused Design Engineering & for launching attacks on the entity the data Enterprise Resource Planning originates from, as well as its partners, (ERP) software & Crypto suppliers, etc. depending on the content of hardware/software & the data. Simulators & Soft/Hardware

Test Tools)

Misuse of CIA Ground: Satellite Control Misuse of device(s) and tools. equipment Centre (group: EGSE/MGSE)

Threats stemming from irrational or

improper behaviour of actors involved in a

satellites' lifecycle. These may include

Negligence of instances of, for example, non-conformity asset handling to security requirements during the design, CIA Human Resources: all assets security configuration, and operation phases of

requirements software and/or hardware components, etc.

which could be a source of vulnerabilities

and open the doors for subsequent threats

and attacks.

Postponing or ignoring security

requirements (e.g. reporting, updates, Ground: all assets patches) by satellite lifecycle actors, due to CIA Space: all assets Refusal of actions negligence or purposeful refusal, may User: all assets affect any segment of satellite lifecycle, due Human resources: all assets to inherent presence of satellite lifecycle

actors in them.

G)

E Threats from unvetted, of insufficiently Ground: Production (L Third Party nonl monitored third parties a satellite's the CIA (Manufacturing & Assembly & compliance supply chain which may result in the Crypto hardware/software & (supply chain) Lega development and delivery of specific Simulators) & Centralised

94

SPACE THREAT LANDSCAPE

March 2025

components that fail to comply or live up to Checkout Systems & Satellite

the security specifications and Operations Centre (Mission

requirements that have access to sensitive Control System)

data or are intended to support critical

satellite functions. Examples include use of

counterfeit or copied software (e.g. pirated

software) that may contain malware, such

as disk wiper malware, or the provision of

hardware components that contain back

doors.

Unauthorised Third parties get access to information from C Space: Payload (PLCOM & access to recycled disposed/recycled media or PDHS & UDHS) or disposed media decommissioned infrastructure.

Ground: Production (Design, Disruption or damage to satellite Failure to maintain development, and quality infrastructure due to a lack of CIA information assurance) & Assembly & maintenance or hardware regeneration at systems Simulators & Satellite Control the asset's End of Life. Centre

Ground: Production

I)

(Manufacturing systems &

LE

( Assembly & Simulators) &

ture Satellite Operations Centre Unpatched/Outdated/Legacy COTS C I (Mission Control System) & truc Legacy Software software deployed among the platform s TTC Ground

ra nf i

y Space: Bus & Payload

c

Lega User: VSAT

95

SPACE THREAT LANDSCAPE

March 2025

ANNEX D – CYBERSECURITY CONTROL FRAMEWORK

Table 18: Policies and Procedures control cluster

Reference Lifecycle # Control title Control Control description Segment framework phase

1 Information Security An Information Security ISP and topic-specific policies, procedures ISO27k All Ground Policies Policy (ISP) and other and other types of documentation are NIST IR 8401 Space relevant cybersecurity defined, approved by management, NIST IR 8411 User policies and guidelines published, communicated to, and SPARTA Human are defined and acknowledged by relevant personnel and Resources documented (e.g. change relevant interested parties, and reviewed management policy, at planned intervals and if significant remote access policy, changes occur. Although primarily focused incident response, and on management aspects of cybersecurity, other) the control has wide applicability across the Threat Taxonomy. 2 Information security Information security roles Information security roles and BSI TR-03184 All Ground roles and and responsibilities are responsibilities are defined, allocated and ISO27k Space responsibilities defined communicated according to the NIST IR 8323r1 User organization needs and the ISP. These NIST IR 8401 Human are also coordinated with third party roles NIST IR 8411 Resources and responsibilities, as applicable. Roles and responsibilities are defined in contractual agreements, which include information security responsibilities that remain valid after termination or change of employment and confidentiality and/or non-disclosure agreements aligned with the organization's information protection requirements The allocation of roles and responsibilities specifies segregation of duties and responsibilities involves separating conflicting duties and areas of responsibility to prevent conflicts of interest or potential misuse of authority, ensuring transparency, accountability, and integrity within the organizational structure. Management requires that all personnel apply information security measures in accordance with the established information security policy, topic-specific policies and procedures of the organization. Although primarily focused on management aspects of cybersecurity, the control has wide applicability across the Threat Taxonomy. 3 Resource allocation Adequate resources are Sufficient resources are assigned NIST CSF 2.0 All Ground allocated commensurate appropriately in alignment with the Space with the cybersecurity risk cybersecurity risk strategy, encompassing User strategy, roles, the designated roles, responsibilities, and Human responsibilities, and policies, thereby ensuring adequate Resources policies. support and funding for effective risk management and mitigation efforts. Although primarily focused on management aspects of cybersecurity, the control has wide applicability across the Threat Taxonomy.

96

SPACE THREAT LANDSCAPE

March 2025

4 Secure Workload-to- Procedures for secure Policies and procedures to ensure that the NASA BPG 1 Ground Workload authentication integration developed or delivered systems do not Space Authenticator protocol are defined and embed unencrypted static authenticators User documented in applications, access scripts, Human configuration files, nor store unencrypted Resources static authenticators on function keys are defined and documented. These also include digital document signatures that ensure authentication of all documents.

97

SPACE THREAT LANDSCAPE

March 2025

Table 19: Compliance control cluster

Reference Lifecycle # Control title Control Control description Segment framework phase

5 Legal, statutory, Legal, statutory, Legal, statutory, regulatory, and BSI Profile for All Ground regulatory, and regulatory, and contractual requirements relevant to Space Space contractual contractual requirements information security and the organization’s ISO27k User requirements relevant to information approach to meet these requirements are NIST CSF 2.0 security and the identified, documented, and kept up to NIST IR 8401 organization’s approach date. This encompasses, but is not NIST IR 8411 to meet these confined to, regulations stemming from the METI requirements are organization's industry and its role within identified, documented, or connection to critical infrastructure, and kept up to date. privacy regulations, and regulations concerning cybersecurity incident reporting, and extra-territorial jurisdiction. 6 Intellectual property Procedures and Suitable measures to safeguarding ISO27k 1, 6 Space rights processes for protecting intellectual property rights are defined and User intellectual property are implemented. This includes developing defined and documented comprehensive protocols to prevent unauthorized access, use, or disclosure of proprietary information, as well as instituting procedures for promptly identifying and addressing any potential infringements or breaches. All employees and relevant stakeholders are educated about the importance of protecting intellectual property and are provided with clear guidelines and training on how to uphold these rights effectively. 7 Independent review Independent review(s) of The organization's strategy for overseeing ISO27k All Ground of information information security information security and its execution, NIST IR 8270 Space security (auditing) are conducted encompassing personnel, procedures, and NIST IR 8411 User technologies, is subjected to periodic independent reviews, scheduled at regular intervals or following notable changes or incidents. Assessments encompass both internal and external cybersecurity audits, along with forensic audits, and extend to suppliers, partners, or other third parties involved. 8 Assessment & Assessment & The assessment and authorization (A&A) SPARTA 1 Ground Authorization Authorization (A&A) process delineates how thoroughly a concept procedures and specific design and implementation adhere processes are defined to a predefined set of security requisites and documented outlined by the organisation and relevant regulatory frameworks and is documented within a formal authorisation package.

Table 20: Risk Management control cluster

Reference Lifecycle # Control title Control Control description Segment framework phase

9 Threat modelling Threat modelling is Threat modelling, attack surface analysis, SPARTA 1 Ground employed to identify and and vulnerability assessment are Space reduce the attack surface employed to guide the development User process, drawing on analysis from similar Human systems, components, or services when Resources relevant. Leveraging identified threats, organisation can work towards minimising the attack surface where feasible. For the space segment, threat modelling considers the lifetime of the system that can be over 15 years and includes analysis of emerging threats stemming for nascent technologies (quantum).

98

SPACE THREAT LANDSCAPE

March 2025

10 Criticality Analysis Criticality analysis is A criticality analysis is performed to SPARTA 1 Ground performed to identify identify mission critical functions, critical Space critical functions, components, and data flows and reduce User components and data the vulnerability of such functions and Human flows components through secure system Resources design. Identification of critical components/functions enables focusing measures for supply chain protection, access management or network security on those most critical. As in control #9, the critically analysis considers the lifetime of the system that can be over 15 years. 11 Adaptive Risk Continuous process of A continuous process for qualitative and NASA BPG All Ground Response and qualitative and quantitative mission security risk analysis Space Resource Allocation quantitative mission and risk response is established and User Function security risk analysis and implemented, spanning the entire duration Human risk response is of the mission. The process includes Resources conducted for the regular assessments to identify potential duration of the mission security threats and vulnerabilities, evaluate their potential impact and likelihood, and prioritize them based on their severity. Effective risk response strategies are defined and implemented to mitigate identified risks, monitor the effectiveness of these strategies, and make necessary adjustments in response to new threats or changes in the mission environment. Continuous training and awareness programs are conducted to ensure all mission personnel are equipped to recognize and address security risks. Regular audits and reviews are performed to ensure compliance with security policies and procedures, and to incorporate lessons learned from past incidents and emerging best practices. 12 Third Party risk Cyber supply chain risk Cyber supply chain risk management METI All Ground management management processes (SCRM) processes are identified, NIST CSF 2.0, Space are defined and established, assessed, managed and NIST IR 8401 User implemented agreed to by organizational stakeholders. NIST IR 8411 These ensure that supply chain risks are identified, assessed, and managed. The SCRM process includes third parties, such as suppliers or partners, who provide information systems, components and/or services. It enables considering and defining multi-supplier strategies (supporting supplier diversification). 13 Risk management Risk management Risk management processes and METI All Ground processes and procedures are defined and implemented, NIST CSF 2.0 Space procedures are defined including risk management objectives, risk NIST IR 8323r1 User and implemented appetite and tolerance thresholds, and NIST IR 8411 Human appropriate risk response options, Resources considering internal and external stakeholders' needs and expectations. Identified threats and vulnerabilities are assessed using a standardised method for calculating, documenting, categorising, and prioritising cybersecurity risks. Processes and procedures for reporting on the current levels of risks are in place.

14 Business Impact Business Impact Analysis Business Impact Analysis (BIA) is ISO27k 1 Ground Analysis (BIA) is conducted during the conducted to identify and assess potential NIST IR 8401 design and development impacts of threats and the likelihood of NIST IR 8411 phase to prevent any their occurrence. It is a crucial process for future vulnerabilities. BCM that identifies and evaluates the potential effects of disruptions on critical business operations. BIA informs the BCM strategy, ensuring that roles and responsibilities are clearly defined, with teams assigned to mitigate risks and

99

SPACE THREAT LANDSCAPE

March 2025

implement effective recovery measures in the event of a disruption.

Table 21: Security by Design control cluster

Reference Lifecycle # Control title Control Control description Segment framework phase

15 Configuration Configurations, including Configurations, including security ISO 27k 1, 2, 6 Ground Management security configurations, configurations, of hardware, software, NIST IR 8270 Space are defined, documented, services, and networks are established, implemented, monitored, documented, implemented, monitored, and reviewed. and reviewed. A baseline configuration of information technology/industrial control systems that incorporates security principles (e.g. concept of least functionality) is created and maintained. The principle of least functionality is incorporated by configuring systems to provide only essential capabilities. 16 Coding Standard Secure coding principles Acceptable coding standards to be used ISO27k 1 Ground for software development by the software developers are defined, SPARTA are defined and including acceptable software implemented to ensure development language. The language proper security constructs should consider security requirements, are in place scalability of the application, the complexity of the application, development budget, development time limit, application security, available resources, etc. The coding standard and language choice must ensure proper security constructs are in place. Automated means to evaluate adherence to coding standards should be employed. The principles also take into account on-board software in terms of code size/computing power required (e.g.; safe memory access/allocation) and potential trade-offs and constraints due to the software's capabilities and runtimes needed to support the language choice. 17 Secure Rules for the secure Principles for engineering secure systems BSI TR-03184 1, 6 Ground Development development of software should be established, documented, ISO 27k Space Lifecycle and systems should be maintained, and applied to any information NIST IR 8270 established and applied. system development activities 18 Cybersecurity-Safe Secure vehicle fault The capability to enter the spacecraft into NASA 1, 5, 6, 7 Ground Mode management functions a configuration-controlled and integrity- SPARTA Space and safe mode operations protected state representing a known, are implemented to operational cyber-safe state (e.g. cyberenable a cyber-safe mode safe mode) is provided. The spacecraft when threats are detected should be able to enter a cyber-safe mode when conditions that threaten the platform are detected. The cyber-safe mode ensures all nonessential systems are shut down and the spacecraft is placed in a known good state using validated software and configuration settings. Within cyber-safe mode, authentication and encryption should still be enabled. The spacecraft should be capable of reconstituting firmware and software functions to preattack levels to allow for the recovery of functional capabilities (by self-healing or supported from the ground). If not possible, a reduced level of mission capability should be achieved. Cyber-safe mode software/configuration should be stored onboard the spacecraft in memory with hardware-based controls and should not be modifiable.

100

SPACE THREAT LANDSCAPE

March 2025

19 Secure Command Spacecraft protection is Additional protection modes for SPARTA 5, 6, 7 Space Mode(s) enhanced by additional commanding the spacecraft are in place. protection modes These may include the spacecraft restricting command lock based on geographic location of ground stations, special operational modes within the flight software, or temporal controls where the spacecraft will only accept commands during certain times. 20 Security of Power Power randomization and Hardware circuits are designed to ensure SPARTA 5, 6 Space Systems power consumption that the hardware module is built into the obfuscation techniques chip that adds noise to the power are employed consumption to mask changes in power consumption. This increases the cost/difficulty of a power analysis attack. Alternatively, obfuscation is performed but it should not degrade operability of the system. These come at an increased cost for manufacturing sensor nodes. Power randomization is not energy efficient and could be impactful for size, weight, and power which is limited on spacecraft as it adds to the fabrication cost of the device. 21 Separation of The development, testing Development, testing, and production ISO 27k 1, 2 Ground Environments and production environments are separated and secured environments are to prevent unauthorized access and separated and secured mitigate the risk of cross-environment contamination. This ensures that changes in development and testing do not impact production systems and maintains the integrity and confidentiality of each environment. Backup systems are equally secured. 22 Change Change management Changes to information processing ISO 27k 6, 7 Ground Management procedures are defined facilities and information systems are NIST IR 8270 Space and documented subject to defined and documented change management procedures. Configuration change control processes are in place.

Table 22: Environmental and Physical Security control cluster

Reference Lifecycle # Control title Control Control description Segment framework phase

23 Transport Security Transport from the The date, the route, the shipping BSI TR-03184 2, 3 Ground integration hall to the test company, and the personnel involved is stations, between kept as secret as possible. Staff should be different facilities, and to instructed and obligated to maintain the start facility is secured secrecy. Use of trustworthy personnel for transport in ensured, accounting for time and security-related conditions for transport. Electronic document exchanges are conducted using protected communication channels or encryption of the information for transmission via open communication channels. Separation of important elements of the satellite during transport should be examined if this is still possible at this stage of integration. It should also be examined whether the selection of suitable tamper measures for individual components or for the transport container is necessary and useful. This also includes ensuring that the containers used for transport are properly secures from different environmental and atmospheric hazards. The services offered by the transport companies, the means of transport provided, or the courier services commissioned are assessed with regards

101

SPACE THREAT LANDSCAPE

March 2025

to their scope of services and execution measured against contractually specified requirements. For further information on supplier reviews, refer to the Supply Chain Management controls.

24 Tamper Protection Physical inspection of Tamper proof protection is employed SPARTA 1, 2, 3 Ground hardware is performed to where possible when shipping/receiving METI identify potential equipment, with physical inspection of tampering hardware performed. Cybersecurity measures for satellite operation and data utilisation facilities – tracking and control station, receiving station, network operation system, and mission control system – are in place (including satellite control system and orbit control system).

Table 23: Network Security control cluster

Reference Lifecycle # Control title Control Control description Segment framework phase

25 Communications Secure communication Secure communication protocols with METI 6 Space Security protocols are employed to strong cryptographic mechanisms are NIST IR 8323r1 User prevent unauthorized employed to prevent unauthorized SPARTA disclosure of, and detect disclosure of, and detect changes to, changes to information information during transmission. Confidentiality and integrity of information during preparation for transmission and during reception is maintained. The spacecraft mode of operations prevents disabling cryptography on the TT&C link (i.e. crypto-bypass mode). Wireless transmissions that are deliberate attempts to achieve imitative or manipulative communications deception based on signal parameters are identified and rejected. Value and relevance of data/information is determined at specific time intervals to ensure that varying levels of encryption complexity are applied. 26 Anti-counterfeit Anti-counterfeit policy and Anti-counterfeit policies and procedures SPARTA 1 Ground Hardware procedures are defined designed to detect and prevent counterfeit and implemented components from entering the information system are documented and implemented. These includes tamper resistance and protection against the introduction of malicious code or hardware. 27 Transmission Transmission security Transmission security solutions and SPARTA 4, 5, 6 Space security solutions and measures measures are employed to prevent are employed to protect interception, disruption of reception, communication communications deception, and/or transmission derivation of intelligence by analysis of transmission characteristics such as signal parameters or message externals. For example, jam-resistant waveforms are utilised to improve the resistance of radio frequency signals to jamming and spoofing.

102

SPACE THREAT LANDSCAPE

March 2025

This is applied to space-space (i.e.: intersatellite links) systems if these space systems have such capability. For the encryption of the group-space communication via RF, please refer to control #39.

28 Disable Physical Physical ports are Data connection ports or input/output SPARTA 1, 2 Ground Ports disabled prior to devices (e.g. JTAG) are disabled or operations removed prior to spacecraft operations. 29 Backdoor Non-critical backdoor An analysis of critical (backdoor/hardware) SPARTA 1, 2 Ground Commands commands are disabled commands that could adversely affect mission success if used maliciously is performed. All viable commands are identified and documented. Only critical commands for the purpose of providing emergency access where commanding authority is appropriately restricted are employed. 30 Resilient Position, Authentication Authentication mechanisms that allow SPARTA 6 Ground Navigation, and mechanisms to verify GNSS receivers to verify the authenticity Space Timing GNSS information of the GNSS information and of the User sources are in place transmitting entity are utilised where possible, to verify trusted sources. Fault-tolerant authoritative time sourcing is in place for the spacecraft to synchronize internal system clocks for each processor when the time difference is greater than the FSW-defined interval. Where the SpaceWire data communication protocol is employed, the spacecraft adheres to mission-defined time synchronization standard/protocol to synchronize time across a SpaceWire network with an accuracy around 1 microsecond. 31 Smart Contracts Smart contracts are used Smart contracts are used to mitigate harm SPARTA 6 Space to enforce security when an attacker is attempting to protocols compromise a hosted payload. Smart contracts stipulate security protocols required across a bus and, if violated, the violator is barred from exchanges across the system after consensus achieved across the network. 32 Communication Alternate physical Alternate physical mediums for networking SPARTA 6 Ground Physical Medium mediums for networking based on the threat model/environment are in place to mitigate are in place. For example, fibreoptic network security concerns cabling is commonly perceived as a better choice in lieu of copper for mitigating network security concerns (e.g. eavesdropping/traffic flow analysis) because optical connections transmit data using light and don’t radiate signals that can be intercepted. 33 Traffic Flow Security Traffic flow security and Techniques to assure traffic flow security SPARTA 6 Ground confidentiality measures and confidentiality are applied to links that are in place to mitigate carry TT&C and/or data transmissions (to traffic analysis attacks include on-board the spacecraft) to mitigate or defeat traffic analysis attacks or reduce the value of any indicators or adversary inferences. These may include methods to pad or otherwise obfuscate traffic volumes/duration and/or periodicity, concealment of routing information and/or endpoints, or methods to frustrate statistical analysis. 34 Access-based The network is Network segmentation is based on the BSI TR-03184 5, 6 Ground network segmented into specifications for network architecture and ISO27k Space segmentation subnetworks to prevent design. Information should not be allowed NIST IR 8323r1 User unauthorised access to flow between partitioned applications NIST IR 8411 unless explicitly permitted by security SPARTA policy. Isolate mission critical functionality

103

SPACE THREAT LANDSCAPE

March 2025

from non-mission critical functionality by means of an isolation boundary (implemented via partitions) that controls access to and protects the integrity of, the hardware, software, and firmware that provides that functionality. Access to physical and logical assets and associated facilities is limited to authorized users, processes, and devices and is managed consistent with the assessed risk. Enforce approved authorizations for controlling the flow of information within the spacecraft and between interconnected systems based on the defined security policy that information does not leave the spacecraft boundary unless it is encrypted. Implement boundary protections to separate bus, communications, and payload components supporting their respective functions. Relevant assets include antennas, receivers, servers, and subscriptions, as well as radio frequency emanations. 35 Cryptography & Rules for the use of Rules for the effective use of BSI TR-03184 1, 2, 6 Ground Crypto Key cryptography are defined cryptography, including cryptographic key BSI Profile for Space Management and implemented; On- management, are defined, and Space board messages are implemented. Only approved ISO27k encrypted cryptographic algorithms, cryptographic SPARTA key generation algorithms or key distribution techniques, authentication techniques, or evaluation criteria are employed. Encryption key handling is performed outside of the onboard software and is protected using cryptography. Encryption keys are restricted and cannot be read via any telecommands. In future deployment of Quantum Key Distribution (QKD) via satellites, consider public key infrastructure (PKI), a combination of quantum-resistant asymmetric cryptographic implementations (PQC) and pre-quantum asymmetric cryptographic solutions, with the use of Field Programmable Gate Arrays (FPGAs) which will allow to reconfigure the encryption algorithms. Frequency of key update and key length/complexity is determined based on the importance/relevance of data being secured - see control #25. In case of detected attacks, or other forms of anomalies and events, existing communication encryption and other measures such as the change of crypto hardware and software, algorithms and keys should be reviewed. In addition to authentication on-board the spacecraft bus, as well as all the network connections, authenticated encryption is also recommended to protect the confidentiality of the data traversing the bus. Ensure basic protections like encryption are still being used on the uplink/downlink to prevent eavesdropping. Lastly, the Inter-Satellite-Link (ISL) which enables satellite to connect to each other and communicate is protected via encryption. 36 On-board Message Encryption of the In addition to authenticating the on-board SPARTA 6 Space Encryption message and the space the spacecraft bus, encryption is also User link recommended to protect the confidentiality of the data traversing the bus. Basic protections like encryption are still being used on the uplink/downlink to prevent

104

SPACE THREAT LANDSCAPE

March 2025

eavesdropping. CCSDS defines and recommends specific protocols, which could be applied in ensuring secure linking; modularity between the existing implementations of the SDL protocols (Telemetry, Telecommand, and Advanced Orbiting Services) and the Space Data Link Security Protocol (SDLS) protocol is envisaged. The latter protects the services offered by the SDL protocols and supports the three security services of Authentication, Encryption, and Authenticated Encryption. 37 Power Masking Power masking is used to Masking is a scheme in which the SPARTA 6 Space protect secret keys intermediate variable is not dependent on User an easily accessible subset of secret key. This results in making it impossible to deduce the secret key with partial information gathered through electromagnetic leakage.

38 Satellite Unit RF Encryption of RF link Implement cybersecurity measures in the SPARTA 1, 6 Space Encryption satellite system (main satellite unit and RF communication). 39 Data encryption Transmitted data (bus- Encryption and transmission security is NIST IR 8323r1 6 User payload link) is encrypted employed in accordance with availability, NIST IR 8411 integrity, and confidentiality requirements. Time protocols may need integrity, authentication, and— for certain use cases — confidentiality protections. Data encryption and decryption practices should be discussed with external organizations. Measures such as error detection, error correction, bulk link encryption and other transport layer protections should be considered. The link between bus and payload is also encrypted / segmented depending on the purpose of the space system (with keys/algorithms used for specific segments).

Table 24: Data Security control cluster

Reference Lifecycle # Control title Control Control description Segment framework phase

40 Information Information is classified Information is classified according to its BSI TR-03184 6 User classification and according to the risk rating from risk assessments, labelled ISO27k labelling assessed risk level and accordingly, and stored in a regularly confidentiality, integrity, maintained data inventory. The assigned and availability needs classification levels are used to determine (CIA), and labelled access rights, acceptable use, and accordingly protection requirements. 41 Data Management Data is protected in all The confidentiality, integrity, and ISO27k All Space states (rest, transit, use) availability of data at rest, in transit, and in NIST CSF 2.0 User use are safeguarded according to the risk NIST IR 8323r1 and classification level. Integrity checks for NIST IR 8401 transferred data utilize checksum or hash- NIST IR 8411 based methods. Data at rest, such as SPARTA backups, is stored securely and separately from the operational system. Procedures for handling data in all states include considerations and requirements for third parties. 42 Data Loss Data Loss Prevention DLP solutions are implemented to ISO27k All Ground Prevention (DLP) solutions and safeguard information assets from NIST IR 8323r1 Space measures are employed unauthorized access, disclosure, and NIST IR 8401 User modification, employing methods such as NIST IR 8411 authentication, information flow isolation, SPARTA access control, and encryption. Physical locations housing critical assets are secured against data leakage.

105

SPACE THREAT LANDSCAPE

March 2025

Additionally, shared system resources like registers, main memory, and secondary storage are sanitized to remove any information previously stored from prior use.

43 Backup There is a defined and Information and data are backed up BSI TR-03184 6 Space implemented process for regularly following established procedures ISO27k User conducting, maintaining, that dictate the frequency, methods, NIST CSF 2.0 and testing backup of responsibilities, and access. These NIST IR 8411 information backups are tested periodically to check SPARTA for errors and verify integrity, ensuring that critical data can be restored after a disruption or incident. 44 Information Lifecycle Information assets are The lifecycle of information assets is BSI TR-03184 All Ground identified and described explicitly outlined, encompassing all ISO27k Space across their lifecycle, relevant processes. Data is retained only NIST IR 8401 User considering all relevant as long as needed to achieve its intended NIST IR 8411 processes purposes, even by third parties. Once the data lifecycle ends, it is destroyed following established procedures to ensure proper sanitization and disposal. 45 Data masking Data masking is Techniques of data masking, both ISO27k 6 Space employed to obfuscate dynamic and static, are used in User original, sensitive data accordance with the existing policies and procedures, the business environment and legislative obligations (e.g. related to personal identifiable information (PII) of satellite lifecycle actors). Data masking techniques may include pseudonymization, anonymization, redaction, and substitution. 46 Real-time physics Real-time physics model- Real-time physics model-based system is SPARTA 6 Space model-based system based system is used to used to verify data inputs to satellite bus verification verify data input and and payload. control sequence changes 47 Process ID Process ID whitelisting is Only a limited list of IDs is allowed to SPARTA 5, 6 Space whitelisting employed in the satellite communicate with and issue commands to the satellite bus and payload firmware.

48 A tamper resistant A tamper resistant body is Sensor nodes are encased in bodies SPARTA 6 Space body used when producing a made from tamper-resistant material. User sensor node

Table 25: Vulnerability Management control cluster

Reference Lifecycle # Control title Control Control description Segment framework phase

49 Malware Protection Mission operated systems Mission operated systems employ BSI TR-03184 1, 2, 6 Ground employ malicious code malicious code protection mechanisms at ISO 27k Space protection mechanisms to information system entry and exit points NASA BPG User detect and eradicate and on system components. These enable malicious code real-time scans of files from external sources on endpoints devices and at network entry/exit points as files are downloaded, opened, or executed to detect and eradicate malicious code, including those inserted through the exploitation of information system vulnerabilities. Mission system software updates are validated as free from malware prior to deployment, launch, and at defined regular intervals while the mission is in operation. Results from malicious code analysis is incorporated into organizational incident response and flaw remediation processes.

106

SPACE THREAT LANDSCAPE

March 2025

50 Vulnerability Vulnerability management Information about technical vulnerabilities ISO 27k 1, 6 Ground Management processes and of information systems in use is collected NIST CSF 2.0 Space procedures are defined and exposure to such vulnerabilities is NIST IR 8270 User and implemented evaluated. Asset vulnerabilities are NIST IR 8323r1 identified, validated, and recorded. There is a defined and implemented process for receiving, analysing, and responding to vulnerability disclosures. A vulnerability management plan is in place covering also vulnerabilities that are potentially inherited from external organisations and assets. 51 Installation of Procedures for software Procedures and measures for securely ISO 27k 1, 2, 3 Ground software on installation on operational managing software installations on NIST CSF 2.0 Human operational systems systems are defined and operational systems are established. NASA BPG Resources implemented These include installing solely tested and BSI TR-03184 authorized software, ensuring releases and installations adhere to specified permissions and procedures, conducted exclusively by authorized personnel, such as within a controlled test environment. Information security needs should be identified, defined, and sanctioned during the development or procurement of applications. 52 Vulnerability Vulnerability scanning is Vulnerability scanning activities are BSI Profile for All Ground scanning used to identify defined and implemented, ensuring they Space Space vulnerabilities do not impact operations. Vulnerability BSI TR-03184 User scanning is used to identify known NIST IR 8270 software vulnerabilities (excluding custom- NIST IR 8401 developed software - ex: COTS and Open- SPARTA Source), and vulnerabilities in dependencies and outdated software (i.e. software composition analysis). Vulnerability scanning tools and techniques facilitate interoperability among tools and automate parts of the vulnerability management process by using standards for: (1) enumerating platforms, custom software flaws, and improper configurations; (2) formatting checklists and test procedures; and (3) measuring vulnerability impact. Ground segment technologies and measures may be employed to perform vulnerability analysis of the space segment. Scans may be performed on test systems rather than the space segment itself. 53 Security Testing Results of penetration Penetration testing and vulnerability BSI TR-03184 1, 6 Ground Results testing and vulnerability scanning results are used to support SPARTA Space scanning are used to identification of detailed vulnerabilities and build report and insight on how to exploit them. vulnerability repositories 54 Software Updates Regular software updates Software updates are regularly performed. BSI TR-03184 All Ground are performed to mitigate Updated versions of the software/firmware SPARTA Space exploitation risk systems incorporating security-relevant updates are released after suitable regression testing, at a frequency no greater than mission-defined frequency. Old versions of software are removed after upgrading but restoration states (i.e. gold images) are recommended to remain on the system. This control also includes the on-board software, and workarounds for maintaining security are to be found at times when it cannot be updated (while in orbit) - see control #19 for potential solutions.

107

SPACE THREAT LANDSCAPE

March 2025

55 Protocol Update / Protocols are updated A protocol is a set of rules (i.e. formats SPARTA 5, 6, 7 Ground Refactoring based on emerging and procedures) to implement and control Space threats and vulnerabilities some type of association (e.g. communication) between systems. Protocols can have vulnerabilities within their specification and may require updating or refactoring based on vulnerabilities or emerging threats (i.e. quantum computing). These apply for space/ground protocols and on-board protocols. 56 Software Source The use of binary or The use of binary or machine-executable SPARTA 1 Ground Control machine-executable code code from sources that do not offer a is controlled warranty or provide source code is prohibited to ensure ability to verify, maintain, and secure the software against potential vulnerabilities. 57 ASIC/FPGA Trusted hardware Application-Specific Integrated Circuit SPARTA 1, 2 Ground Manufacturing development is ensured (ASIC) / Field Programmable Gate Arrays are developed by accredited trusted foundries to limit potential hardware-based trojan injections. 58 Integrity Checking Integrity checking Integrity checking mechanisms are used to NASA BPG 1, 2, 5, 6 Ground and Assurance mechanisms are used to validate the integrity of mission software, NIST IR 8323r1 Space verify software, firmware programmable logic devices, and NIST IR 8411 User and information integrity firmware, as well as proper management of information and records, aligning with the risk strategy and the requirements for protecting information confidentiality, integrity, and availability.

Table 26: Access Management control cluster

Reference Lifecycle # Control title Control Control description Segment framework phase

59 Computing Device Computing devices are Computing devices, including mobile NASA BPG All Ground Authentication authenticated before devices and network connected endpoint Space network connections are devices (e.g. workstations, printers, User established servers, VoIP Phones, VTC CODECs) are Human uniquely identified and authenticated Resources before establishing a network connection. 60 Access control Access control policies Rules to control physical and logical ISO27k All Human and procedures are access to information and other NASA BPG Resources defined and documented associated assets are established and NIST CSF 2.0 implemented based on business and NIST IR 8323r1 information security requirements. The NIST IR 8401 rules incorporate security best practice NIST IR 8411 such as least privilege, separation of SPARTA duties and the four-eyes principle and target all relevant systems and subsystems in the satellite lifecycle. Additionally measures to implement physical access control include badge with pins, guards, gates, etc. 61 Identity Identities are managed Identities and credentials are issued, ISO27k All Human management throughout their lifecycle managed, verified, revoked and audited NASA BPG Resources for authorized devices, users and NIST CSF 2.0 processes. Identities are proofed and NIST IR 8270 bound to credentials and asserted in NIST IR 8323r1 interactions. Each identity is verified prior NIST IR 8401 to provisioning authenticators. For long NIST IR 8411 term project all historical records are kept, and in cases of users being involved in several phases of the lifecycle, at different time points with different level of credentials, the identities and credentials are recorded and managed. 62 Authentication Allocation and Allocation and management of ISO27k All Human information management of authentication information is governed by Resources management authentication information a management process, including advising governed by a personnel on the appropriate handling of management process, authentication information

108

SPACE THREAT LANDSCAPE

March 2025

including guidance for personnel on proper handling.

63 Access rights Access control policies Access control policies and procedure ISO27k All Human and procedure determining access rights to information Resources determining access rights and associated assets are defined and to information and implemented. Access rights to information associated assets are and other associated assets is defined and implemented provisioned, reviewed, modified and removed in accordance with the organization’s topic-specific policy on and rules for access control. Privileged access rights are restricted and managed, including privileged utility programmes. Read and write access to source code, development tools and software libraries should be appropriately managed. 64 Authentication Authentication Users, devices, and other assets are ISO27k All Human procedures are defined authenticated (e.g. single-factor, multi- NASA BPG Resources and documented factor) commensurate with the risk of the NIST CSF 2.0 transaction (e.g. individuals’ security and NIST IR 8270 privacy risks and other organizational NIST IR 8323r1 risks). Communication sessions (crosslink NIST IR 8401 and ground stations) are authenticated for NIST IR 8411 all commands before establishing remote SPARTA connections using bidirectional authentication that is cryptographically based. Adding authentication on the spacecraft bus and communications on-board the spacecraft is also recommended. 65 Remote access Remote access Remote access is managed, including the BSI TR-03184 All User management management procedure possible remote deletion function. NIST IR 8270 and processes are NIST IR 8323r1 defined and documented NIST IR 8401 NIST IR 8411 66 Multi factor The zero-trust concept is Multi-Factor Authentication is employed. NASA BPG All Human authentication applied to access Zero-trust access controls to the code SPARTA Resources management repositories are employed where possible. For example, the main branches in repositories are protected from injecting malicious code. 67 Relay Protection Relay and replay- Relay and replay-resistant authentication SPARTA 1, 6 Space resistant authentication mechanisms for establishing a remote mechanisms and connection or connections on the employed spacecraft bus are employed. 68 Session Termination Procedures for session User sessions are defined and SPARTA 6 Space termination are implemented. Connections associated with established a communications session are terminated at the end of the defined session or after an acceptable amount of inactivity which is established via the concept of operations. 69 Insider Threat Insider Threat procedures Policies and procedures to prevent SPARTA All Human Protection and guidelines are individuals (i.e. insiders) from Resources defined and documented masquerading as individuals with valid access to areas where commanding of the spacecraft is possible are defined and documented. An Insider Threat Programme is established to aid in the prevention of people with authorised access performing malicious activities. 70 Restricted zones Informal meeting places Meeting places within the restricted zone BSI TR-03184 All Human access within restricted zones (coffee, smoking corners, etc.) are Resources are defined defined, minimising access e.g. to avoid tailgating. 71 Password security A password policy and A clear password policy is defined and BSI TR-03184 All Human guidelines are defined documented. Resources and documented

109

SPACE THREAT LANDSCAPE

March 2025

Table 27: Asset Management control cluster

Reference Lifecycle # Control title Control Control description Segment framework phase

72 Asset Inventory An asset inventory if An inventory of information and other BSI TR-03184 1 Ground established and associated assets (hardware and ISO27k Space maintained software) is developed and maintained, NIST CSF 2.0 User including asset owners and dependencies NIST IR 8401 Human between assets. The inventory should also NIST IR 8411 Resources include assets provided or managed by SPARTA third parties, including tools used for project management and day-to-day business operations. 73 Return of assets A procedure for asset A procedure for asset management ISO27k All Ground management following following termination of cooperation is Space termination of cooperation defined and documented, including User is defined and requirements for personnel and other Human documented interested parties to return all the Resources organizational assets in their possession upon change or termination of their employment, contract, or agreement 74 Equipment Procedures and Procedures and processes for equipment ISO27k All Ground maintenance processes for equipment maintenance are defined and implemented Space maintenance are defined ensuring equipment is maintained User and implemented correctly to ensure availability, integrity, Human and confidentiality of information. Resources

75 Secure disposal or Procedures and Procedures and processes for disposal/re- ISO27k 7 Space re-use of equipment processes for disposal/re- use of equipment are defined and User use of equipment are implemented ensuring items of equipment defined and implemented containing storage media are verified to ensure that any sensitive data and licensed software has been removed or securely overwritten prior to disposal or reuse. This also includes the use of a "kill switch" that prevents hijacking of assets that have been disposed. 76 Asset prioritisation Guidelines for asset Guidelines for asset prioritisation are BSI TR-03184 All Ground prioritisation are defined defined and documented. Assets are ISO27k Space prioritised and protected based on their NIST CSF 2.0 User classification, criticality, resources, and NIST IR 8323r1 impact on the mission. NIST IR 8411

77 Asset lifecycle Guidelines and Assets (systems, hardware, software, NIST CSF 2.0 6, 7 Ground management procedures for the asset services, and data) are managed NIST IR 8323r1 Space management lifecycle are throughout their life cycles. Management NIST IR 8401 User defined and documented takes into account cybersecurity best NIST IR 8411 practice and implications of other activities, such as risk management and others as well as the asset classification. Maintenance and repair of organizational assets are performed and logged, with approved and controlled tools.

110

SPACE THREAT LANDSCAPE

March 2025

Table 28: Supply Chain Management control cluster

Reference Lifecycle # Control title Control Control description Segment framework phase

78 Supplier Security Supplier or Third-Party Subcontractors and participating BSI Profile for 1, 2, 3, 4 Ground Management compliance with relevant companies are required to provide Space security standards is evidence of security management or METI reviewed established security standards. If required, a review of compliance with the applicable rules and standards is conducted via an ISMS self-assessment or an audit. The scope of the security standard should be examined in the relevant areas. 79 Software Version Version numbers of The version numbers of deployed COTS SPARTA 1, 2 Ground Numbers COTS or Open-Source or Open-Source are adequately protected. are protected These numbers can be cross referenced against public repos to identify Common Vulnerability Exposures (CVEs) and exploits available. 80 Software Bill of The Software Bill of The Software Bill of Materials (SBOM) is SPARTA 1 Ground Materials Materials (SBOM) is generated against the entire software generated to identify supply chain and cross correlated with known vulnerabilities known vulnerabilities (e.g. Common Vulnerabilities and Exposures) to mitigate known vulnerabilities. 81 Software Supply Technical measures are Integrity of the supply chain is ensured BSI TR-03184 1, 2 Ground Chain Integrity in place to ensure through various means including technical NIST IR 8401 integrity of the supply measures (e.g. hash sum), organisational chain measures (e.g. sealed letters, personal handover) as well as auditing of suppliers. Response and recovery planning and testing are conducted with suppliers and Third-Party providers. 82 Cloud Cybersecurity SLAs are in place Selection of external and Cloud-related ISO 27k 1, 2, 6 Ground Measures external services and services is based on the level to which METI Space cloud providers security requirements and service level User agreements (SLAs) are met, in relation to applicable laws, regulations and the mission itself. 83 Outsourced Activities related to All activities related to outsourced system ISO 27k All Ground development outsourced system development are directed, monitored, and NIST IR 8270 Space development are monitor reviewed to ensure compliance with NIST IR 8323r1 User and reviewed security, quality, and performance NIST IR 8411 standards. This includes overseeing the SPARTA development process, evaluating the adherence to contractual obligations, and conducting regular audits to mitigate risks associated with outsourcing. Conduct supplier review prior to prior to entering into a contractual agreement with a contractor (or sub-contractor) to acquire systems, system components, or system services. Their role in the supply chain is identified and communicated. Providers of information systems, components and services are identified, prioritised, and continuously assessed using a cyber supply chain risk assessment process. If components/software cannot be procured from the original component manufacturer or their authorized franchised distribution, the contract is approved by the supply chain board or equivalent to prevent and detect counterfeit and fraudulent parts, materials, and software. Note that the supply chain risk management (SCRM) is typically an intra-organization function.

111

SPACE THREAT LANDSCAPE

March 2025

Table 29: Monitoring and Alerting control cluster

Reference Lifecycle # Control title Control Control description Segment framework phase

84 Network and Communications are Communications are monitored at the NASA 6 Ground Communications monitored to identify external boundary of the system and at NIST IR 8323r1 Space Monitoring Function cybersecurity events and mission critical internal boundaries within NIST IR 8401 verify the effectiveness of the system. The information system and protective measures assets are monitored to identify cybersecurity events and verify the effectiveness of protective measures. The granularity of the monitoring and the depth of the analysis is consistent with the findings of the risk assessment. Monitoring is performed on the interface to the bus or payload; the receivers that process and form the commands; responses and telemetry; the processed telemetry; and state of health information from the space segment. Additionally, cyber-related events spanning over multiple work shifts should be detected and communicated effectively across all shifts and potentially varying time-zones. 85 Intrusion Detection On-board Intrusion Normal activities on the network for BSI Profile for 4, 5, 6 Ground and Prevention detection/prevention accessing and controlling mission Space Space systems (IDP/IPS) are applications and capabilities are identified BSI TR-03184 employed to detect and and documented. On-board intrusion NASA BPG respond to threats and detection/prevention systems (IDP/IPS) SPARTA attacks that monitor the mission critical components or systems and audit/logs actions are employed. The IDS/IPS have the capability to respond to threats (initial access, execution, persistence, evasion, exfiltration, etc.) and it to address signature-based attacks. The IDS/IPS are integrated traditional fault management to provide a holistic approach to faults onboard the spacecraft. The spacecraft should have capacity to select and execute countermeasures that are compatible with the system’s fault management system to avoid unintended effects or fratricide on the system (i.e. ‘safe countermeasures’). At minimum, the response should ensure vehicle safety and continued operations. Ideally, the goal is to trap the threat, convince the threat that it is successful, and trace and track the attacker — with or without ground support. This would support successful attribution and evolving countermeasures to mitigate the threat in the future. For further information on monitoring and alerting, refer to the Monitoring & Alerting controls. 86 Event detection Event detection is Detected events are communicated to NIST IR 8323r1 6 Ground communication communicated to personnel, partners, analytics, and stakeholders downstream application users. For example, ground antenna data anomalies are communicated together with the current best estimate of data quality. When the cause of a service disruption event is suspected to be external, event detection is shared with appropriate external stakeholders for further investigation.

112

SPACE THREAT LANDSCAPE

March 2025

87 Anomaly detection Event data is correlated Audit/log records are determined, NIST IR 8323r1 4, 5, 6 Ground from multiple sources and documented, implemented, and reviewed NIST IR 8270 communicated; in accordance with documented policies NASA BPG Inappropriate or malicious and procedures. A baseline of network SPARTA activity within the operations and expected data flows for mission’s systems is users and systems is established and detected managed. Event data are collected and correlated from multiple sources and sensors. The network is monitored to detect potential cybersecurity events, including malicious code. Capabilities are in place to enable detection of inappropriate or malicious activity within the mission’s systems and provide alerts upon detection. Automated mechanisms are employed to maintain and validate baseline configuration to ensure the spacecraft's configuration is up-to-date, complete, accurate, and readily available. 88 Mission Cyber Actor An on-board cyber actor An on-board cyber actor actions detection NASA BPG 6 Space Actions Detection actions detection function function is included in the mission’s is in place defined requirements and the resulting system. 89 Critical Telemetry Critical telemetry points Defined critical telemetry points are BSI Profile for 5, 6 Space Points Monitoring are monitored for monitored for malicious activities (e.g. Space malicious activities jamming attempts, commanding attempts BSI TR-03184 – command modes, counters, etc.). This SPARTA includes valid/processed commands as well as commands that were rejected. Telemetry monitoring is synchronised with ground-based Defensive Cyber Operations (i.e. SIEM/auditing) to create a full space system situational awareness from a cybersecurity perspective. 90 Reinforcement A reinforcement learning A reinforcement learning agent is BSI Profile for 5, 6 Space Learning agent is deployed to deployed to detect anomalous events and Space detect anomalous events redirect processes to proceed by ignoring BSI TR-03184 malicious data/input. SPARTA 91 Space-Based Radio Space-based RF Space-based RF mapping is deployed to BSI Profile for 5, 6 Space Frequency Mapping mapping is in place to monitor and analyse the RF environment Space monitor and analyse the that affects space systems both in space BSI TR-03184 RF environment and on Earth. The space-based RF SPARTA mapping provides space operators with a more complete picture of the space environment, the ability to quickly distinguish between intentional and unintentional interference, and the ability to detect and geolocate electronic attacks. RF mapping allows better characterisation of jamming and spoofing attacks from Earth or from other satellites so that other defences can be more effectively employed. 92 Continuous Personnel activity is Personnel activity and technology usage NIST CSF 2.0 All Human Personnel monitored to detect are monitored to detect potentially adverse Resources Monitoring anomalous behaviours events. 93 Dependency Protections are in place Proper protections are in place for SPARTA 6 User Confusion for mitigating dependency ensuring dependency confusion is confusion mitigated. This includes assurance that internal dependencies are pulled from private repositories vice public repositories, that the CI/CD/development environment is secure and validation of dependency integrity by ensuring checksums match official packages. 94 Security Information Logs of security-relevant Security-related events within system BSI TR-03184 6 Space and Event events are integrated into management are systematically recorded NIST IR 8323r1 User Management (SIEM) a Security Information and integrated into a Security Information / Security Operations and Event Management and Event Management (SIEM) system, Center (SOC) (SIEM) system allowing for real-time monitoring and analysis of potential security threats or breaches. Timely detection and response

113

SPACE THREAT LANDSCAPE

March 2025

to identified security incidents within the infrastructure is enabled.

Table 30: Incident Response control cluster

Reference Lifecycle # Control title Control Control description Segment framework phase

95 Public relations Information distribution Information distribution during an incident NIST IR 8323r1 6 User management during during an incident is is centralised and coordinated and the NIST IR 8401 incidents centralised and public-facing representation of the coordinated. organisation is managed. This includes, but is not limited to: - media interactions - handling and ‘triaging’ phone calls and email requests - matching media requests with appropriate and available internal experts - screening all of the information provided to the media 96 Incident Response Procedures and Incident response procedures and BSI Profile for 6 User Plan processes for Incident processes are defined and documented in Space Response are defined an Incident Response Plan. The Incident BSI TR-03184 and documented Response Plan describes in detail the ISO27k process of recovery after a cybersecurity NIST IR 8270 incident, including the specific actions NIST IR 8323r1 which need to be taken and the roles and NIST IR 8401 responsibilities of stakeholders involved. This includes: - Incident identification - Conditions for activation and communication of incident response plan - Incident analysis - Categorization of incidents - Incident containment - Incident mitigation - Information collection and post-mortem (forensic) analysis, including incident categorization The Incident Response Plan is regularly reviewed and updated, based on current trends and developments in technology and threat landscape, regulatory requirements and lessons learned from the materialized incidents. Additionally, adding Security Information and Event Management (SIEM) measure could enhance threat visibility and response times. SIEM can help centralise logs, identify patterns, and trigger alerts, giving the incident response team immediate insights. 97 Incident Thresholds Incident thresholds are Incident thresholds are defined and NIST IR 8323r1 6 Ground defined and documented documented based on an understanding based on an of potential impact to the mission enabling understanding of potential proper reporting, alerting thresholds, and impact the development of adequate incident alert procedures. Required notification or alarm communication time upon nearing and exceeding thresholds is defined and documented.

114

SPACE THREAT LANDSCAPE

March 2025

Table 31: BCM/Disaster Recovery control cluster

Reference Lifecycle # Control title Control Control description Segment framework phase

98 Emergency power Emergency power The function of security equipment and the BSI TR-03184 All Ground sources generators and UPS availability of critical installations are Space systems are in place - guaranteed in the event of power failures User power chain is available to avoid damage due to uncontrolled and dimensioned properly power failures. In addition to the general solutions such as UPS & generators, the whole power chain (power grid lines, transformers, UPS, generators) are available and dimensioned properly. 99 Incident Recovery Procedures and Incident Recovery procedures and BSI TR-03184 6 Space Plan processes for Incident processes are defined and documented in NIST IR 8270, User Recovery are defined and an Incident Recovery Plan. It Incident NIST IR 8323r1 documented Recovery Plan describes in detail the NIST IR 8401 recovery after a cybersecurity incident, including the specific actions which need to be taken and the roles and responsibilities of stakeholders involved. These Incident Recovery Plan is regularly reviewed and updated, based on current trends and developments in technology and threat landscape, regulatory requirements and lessons learned from the materialized incidents. Additionally, global drills are performed to assess the staff's capability to respond to incident, as well as drills for specific categories of staff. 100 Cabling security A secure cabling protocol Cables carrying power, data or supporting ISO27k 3, 4, 5, 6 Ground is defined information services are protected from User interception, interference, or damage.

101 Critical Services Resilience requirements Resilience requirements supporting the NIST IR 8401 6 User Delivery to support delivery of delivery of critical services are established Requirements critical services are for all operating states (e.g. under established for all duress/attack, during recovery, normal operating states operations). Resilience requirements are defined based on the ability for the space segment to function autonomously, the criticality of the services provided by the payload, the system’s architecture, and procedural considerations (e.g. recovery time, periods of outage). 102 Capacity to ensure The required level of Command, response, and telemetry tend BSI TR-03184 6 Ground availability availability and capacity to be low-bandwidth operations and the ISO27k Space for the ground segment is command link is sensitive to delay and NIST IR 8270 User maintained and jitter. All services and communications NIST IR 8323r1 established pathways to and from the spacecraft are NIST IR 8401 examined to ensure they have adequate capacity to handle peak throughput requirements. Cyber/counterspace-relevant cases are considered when determining peak command and telemetry throughput for system sizing. Cyber-relevant cases may include downtime at one site shifting additional throughput to another site or provider. Contingency cases may require highvolume interaction with the vehicle for activities such as root cause analysis or anomaly response. Measures for addressing such cases may encompass high-availability networks, additional power sources, air-conditioning systems, redundant frequencies, load balancers, hot-swaps, and others.

115

SPACE THREAT LANDSCAPE

March 2025

103 System redundancy Redundancy is introduced Due to the sensitivity of space NIST IR 8401 6 Ground for critical infrastructure communication ground segment Space and data is backed up organizations employ one or more User redundant facilities which include transmitters, receivers, and servers that are fully backed up (with critical databases, reference software, gold codes, keys etc.). These facilities need to be subject to the same level of cybersecurity protection as primary ones. In a disastrous event, the redundant infrastructure and the backed-up data can generate commands, process telemetry, and other critical operations. Additionally, redundancy can be achieved through interoperability across different systems and solutions used by different providers. For data-related backup please refer to control #44.

Table 32: Capacity Building control cluster

Reference Lifecycle # Control title Control Control description Segment framework phase

104 Information sharing Information is actively Information on suspected intentional ISO 27k All Ground shared to achieve interference is shared with stakeholders NIST IR 8270 Space broader cybersecurity and relevant organisation in the respective NIST IR 8401 User situational awareness region where the operator is located through appropriate channels and procedures to support broader cybersecurity situational awareness. If agreed upon between stakeholders, common data formats are employed for information sharing to strengthen the protection of the user community. 105 Cybersecurity Cybersecurity is included Specialized cybersecurity personnel, BSI TR-03184 All Human awareness and in human resources including privileged users, receive ongoing NIST CSF 2.0 Resources training practices and personnel awareness and training to equip them with NIST IR 8323r1 are provided with the necessary knowledge and skills to NIST IR 8401 awareness and training undertake their duties with cybersecurity NIST IR 8411 risks in consideration. The content of SPARTA these training materials is regularly refreshed to reflect current trends and advancements in technology and the threat landscape, updated regulatory standards, and insights gleaned from past incidents. 106 Cyber threat Cyber threat intelligence Cyber threat intelligence is collected to BSI TR-03184 All Ground intelligence is collected and analysed enhance the organization's cybersecurity NIST IR 8270 Space posture continually. This intelligence is NIST IR 8323r1 User commonly sourced from various outlets, NIST IR 8401 including information-sharing forums, and NIST IR 8411 analysed to discern attack targets and methodologies.

Table 33: Testing control cluster

Reference Lifecycle # Control title Control Control description Segment framework phase

107 Software Mission Assurance activities are Procedures and technical methods for ISO 27k All Ground Assurance performed according to performing software assurance are Space documented procedures documented and implemented. Audit tests User and other assurance activities involving assessment of operational systems should be planned and agreed between the tester and the mission’s management. 108 Software and End to end testing is Procedures and technical methods for NASA BPG 5, 6 Space Hardware Testing performed according to conducting end to end testing are Function documented procedures documented and implemented. These include negative testing (i.e. abuse cases) of the mission hardware and software as it

116

SPACE THREAT LANDSCAPE

March 2025

would be in an operating state (‘test as you fly’). 109 Dynamic Code Dynamic Code Analysis is Dynamic code analysis is performed to SPARTA All Ground Analysis performed to identify identify software/firmware weaknesses Space software/firmware and vulnerabilities in developed and User weaknesses and incorporated code (open source, vulnerabilities commercial, or third-party developed code). Testing may include simulation, penetration testing, and fuzzing, among other. Testing should be conducted (1) on potential system elements before acceptance; (2) as a realistic simulation of known adversary tactics, techniques, procedures (TTPs), and tools; and (3) throughout the lifecycle on physical and logical systems, elements, and processes. Lab-based learning boards (FLATSATs) as well as digital twins can be used to perform the dynamic analysis depending on the TTPs being executed. Digital twins via instruction set simulation (i.e. emulation) provide a robust environment for dynamic analysis and TTP execution. 110 Static Code Analysis Static Code Analysis is Static source code analysis is performed SPARTA 1, 2, 3 Ground performed to identify for all available source code looking for system-relevant system-relevant weaknesses using no less weaknesses than two static code analysis tools. A prioritised list of software weakness classes (e.g. Common Weakness Enumerations, CWE) is defined and documented based on system-specific considerations and used during static code analysis for prioritisation of static analysis results. 111 Long Duration Long Duration Testing is Testing is performed using hardware or SPARTA 6 Space & Testing performed to identify race simulation/emulation where the test User conditions and time- executes over a long period of time (30+ based attacks days). This testing is aimed at identifying race conditions and time-based attacks. 112 Machine Learning Data integrity testing is The integrity of training data sets for AI/ML SPARTA 6 User Data Integrity performed on AI/ML is used for mission critical operations is training datasets tested to ensure there is no data poisoning. Countermeasures that could either block attack attempts or detect malicious inputs before the training cycle occurs are identified and implemented. Regression testing over time, validity checking on data sets, manual analysis, and/or statistical analysis to find potential injects are employed to detect anomalies. 113 OSAM Dual Multi-factor authentication Before engaging in a On-orbit Servicing, SPARTA 1, 6, 7 Ground Authorization is employed for OSAM Assembly, and Manufacturing (OSAM) servicers mission, verification of servicer should be multi-factor authenticated/authorized by both the serviced ground station and the serviced asset. 114 Simulation Testing The resilience of The simulation of information security BSI Profile for All Ground segments is tested using related attacks (e.g. penetration testing & Space Space attack simulations across threat simulations) should be carried out User the lifecycle during various segments, the integration, Human and the operational phase taking into Resources account the ground segment. In the case of particularly vulnerable missions, an attack simulation should also be considered on the check-out system, transport, launch setup, and the phase of the launch campaign. Existing simulators include SPARTA Cyber Exploiter (SPACE) Invader, and from ESA: Ground to Space Threat Simulator (GSTS).

117

SPACE THREAT LANDSCAPE

March 2025

115 Detection processes Event detection Periodic testing is performed to verify the NIST IR 8323r1 3, 4, 5, 6 Ground are tested processes are tested to performance of detection processes Space ensure they are operating against the most current threat profiles as intended and vulnerabilities. Devices and components that are upgraded are revalidated with end-to-end user testing.

Table 34: Continuous Improvement control cluster

Reference Lifecycle # Control title Control Control description Segment framework phase

116 Detection Processes Detection processes are Detection processes are continuously NIST IR 8323r1 All Ground continuously improved improved and are maintained and tested NIST IR 8411 Space to promote awareness of anomalous User events. This includes maintenance, testing and updating of relevant processes and procedures deployed on information systems and assets as well as analytic processes. 117 Oversight and Results of organization- Cybersecurity risk assessment results are NIST CSF 2.0 All Ground governance wide cybersecurity risk reviewed to inform and adjust the Space management activities organisation’s risk strategy and direction. User and performance are Improvements to organizational used to inform, improve, cybersecurity risk management processes, and adjust the risk procedures and activities are identified management strategy. across all security capabilities.

Table 35: Defence Capabilities control cluster

Reference Lifecycle # Control title Control Control description Segment framework phase

118 Manoeuvrability Satellite evasive Satellite manoeuvre is an operational SPARTA 6 Space manoeuvre protocols are tactic that can be used by satellites fitted implemented with chemical thrusters to avoid kinetic and some directed energy ASAT weapons. For unguided projectiles, a satellite can be commanded to move out of their trajectory to avoid impact. If the threat is a guided projectile, like most direct-ascent ASAT and co-orbital ASAT weapons, manoeuvre becomes more difficult and is only likely to be effective if the satellite can move beyond the view of the onboard sensors on the guided warhead. 119 Defensive Jamming Jammers and spoofers A jammer or spoofer can interfere with SPARTA 6 Space and Spoofing are employed for sensors on an approaching kinetic ASAT defensive operations weapon, impairing its ability to navigate accurately during the terminal phase of flight. When combined with manoeuvring, this tactic enables a satellite to evade a kinetic attack effectively. Such systems could also deceive SDA sensors by manipulating the reflected radar signal, altering the perceived location, velocity, and quantity of detected satellites, resembling digital radio frequency memory (DRFM) jammers utilized in numerous military aircraft. Additionally, a spacebased jammer might disrupt an adversary's communication capabilities.

118

SPACE THREAT LANDSCAPE

March 2025

120 Deception and Deception and decoys Deception tactics can be utilized to hide or SPARTA 6 Space Decoys are employed for mislead regarding a satellite's location, defensive capabilities capability, operational status, mission type, and/or robustness. Public messaging, like launch announcements, might restrict information or actively spread misinformation about satellite capabilities, and operational techniques can obscure certain capabilities. Another tactic could involve altering satellite capabilities or payloads while in orbit. Satellites with interchangeable payload modules could deploy on-orbit servicing vehicles to periodically transfer payloads between satellites, complicating adversaries' targeting calculations by obscuring which payload is on which satellite. Additionally, satellites may employ tactical decoys to confuse ASAT weapon sensors and SDA systems. These decoys, such as inflatable devices mimicking satellite characteristics or electromagnetic decoys simulating RF signatures, are akin to aircraft using airborne decoys like the ADM-160 Miniature Air-launched Decoy (MALD). 121 Antenna Nulling and Antenna nulling and Satellites can incorporate antennas SPARTA 6 Space Adaptive Filtering adaptive filtering are designed to suppress signals from specific employed for defensive regions on the Earth's surface or areas in operations space where jamming is detected, a technique known as 'nulling'. While nulling can effectively counter jamming from identifiable locations, it may inadvertently block transmissions from friendly users within the nullified area. Conversely, adaptive filtering is employed to suppress particular frequency bands irrespective of their source. This method proves advantageous when jamming consistently occurs within certain frequency ranges, allowing satellite transmissions to proceed uninterrupted. However, the efficacy of adaptive filtering may diminish if a wideband jammer disrupts a significant portion of the utilized spectrum, potentially compromising overall system performance. 122 Physical Seizure Space traffic control and A spacecraft equipped for docking, SPARTA 6 Space debris mitigation manipulating, or manoeuvring other protocols are established satellites or debris can be deployed to prevent space-based attacks or alleviate their aftermath. This system could seize a threatening satellite used for hostile actions or rescue a disabled or hijacked satellite. It could also gather and eliminate harmful orbital debris generated by an attack. However, a key constraint is that each satellite's capability is limited by time and propellant, particularly depending on its orbit. For instance, a satellite stationed in GEO might not be well-suited to capture an object in LEO due to the substantial propellant required for repositioning. Therefore, physical seizure satellites might need to be stationed on Earth and dispatched to a specific orbit when required to counter a particular threat. 123 Filtering and Filters and shutters are On remote sensing satellites, filters and SPARTA 6 Space Shuttering employed to protect shutters serve to safeguard sensors from sensors from laser laser interference. Filters shield sensors dazzling and blinding by permitting only specific wavelengths of light to pass through, but they are less effective against lasers operating at the same wavelengths the sensors are

119

SPACE THREAT LANDSCAPE

March 2025

designed to detect. Shutters, on the other hand, rapidly obstruct or redirect all light to a sensor when an anomaly is detected or a threshold is reached, mitigating potential damage but temporarily interrupting data collection.

124 Defensive Laser systems are Laser systems can be employed to impair SPARTA 6 Space Dazzling/Blinding employed to dazzle or or incapacitate the optical or infrared blind the optical or sensors of an approaching ASAT weapon infrared sensors of ASAT during its terminal phase. This tactic weapons. resembles the use of laser infrared countermeasures on aircraft to counter heat-seeking missiles. By disabling the guidance system of an ASAT weapon and potentially manoeuvring to a different position, a satellite could evade a kinetic attack effectively. Additionally, such systems could hinder inspector satellites' ability to image a satellite seeking to conceal its capabilities or disrupt adversary space domain awareness efforts. 125 Protective Mechanisms to ensure Mechanisms such as failsafe systems, NIST 8401 6 Space Technology resilience requirements load balancing, and hot swapping are NIST 8411 are defined and employed implemented to meet resilience requirements under both normal and adverse conditions.

120

-N -EN -007 -25 -01 TP ABOUT ENISA The European Union Agency for Cybersecurity, ENISA, is the Union’s agency dedicated to achieving a high common level of cybersecurity across Europe. Established in 2004 and strengthened by the EU Cybersecurity Act, the European Union Agency for Cybersecurity contributes to EU cyber policy, enhances the trustworthiness of ICT products, services and processes with cybersecurity certification schemes, cooperates with Member States and EU bodies, and helps Europe prepare for the cyber challenges of tomorrow. Through knowledge sharing, capacity building and awareness raising, the Agency works together with its key stakeholders to strengthen trust in the connected economy, to boost resilience of the Union’s infrastructure, and, ultimately, to keep Europe’s society and citizens digitally secure. More information about ENISA and its work can be found here: www.enisa.europa.eu. ISBN 978-92-9204-696-5 DOI: 10.2824/8841206

Fotnoter

  1. 1 Online Index of Objects Launched into Outer Space. United Nations Office for Outer Space Affairs. https://www.unoosa.org/oosa/osoindex/index.jspx?lf_id= 2 Active satellite orbiting data. Orbiting Now. https://orbit.ing-now.com/ 3 Who owns all the satellites. SatelliteXplorer. https://geoxc-apps.bd.esri.com/space/satellite-explorer/ 4 Space Supporting the Sustainable Development Goals. United Nations Office for Outer Space Affairs. https://www.unoosa.org/oosa/en/ourwork/space4sdgs/index.html 5 EU Space 4 green and digital transition. 2021. EUSPA. https://www.euspa.europa.eu/newsroom-events/news/eu-space-4green-and-digital-transition 6 Euroconsult. 2023. Satellites to be Built & Launched, 26th edition. https://digital-platform.euroconsultec.com/product/satellites-to-be-built-launched/ .Publicly available summary available here: https://www.euroconsultec.com/press-release/four-tons-of-satellites-to-be-launched-daily-by-2032-demand-concentrates-by-a-handful-of-players/. 7 ENISA. 2023. ENISA Foresight Cybersecurity Threats for 2030. https://www.enisa.europa.eu/publications/enisa-foresightcybersecurity-threats-for-2030 NASA. 19 January 2024. Space Security: Best Practices Guide (BPG). https://swehb.nasa.gov/display/SWEHBVD/7.22+- +Space+Security%3A+Best+Practices+Guide?preview=/146540183/154501144/Space%20Security%20Best%20Practices %20Guide%20BPG%20REV%20B.pdf 9 European Cooperation for Space Standardization. 1 July 2024. Space engineering – Security in space systems lifecycles. ECSS-E-ST-80C. https://ecss.nl/standard/ecss-e-st-80c-space-engineering-security-in-space-systems-lifecycles/
  2. 10 Howell O'Neil, P. 2022. Russia hacked an American satellite company one hour before the Ukraine invasion. https://www.technologyreview.com/2022/05/10/1051973/russia-hack-viasat-satellite-ukraine-invasion/ 11 Burgess, M. 10 August 2022. The Hacking of Starlink Terminals Has Begun. Wired. https://www.wired.com/story/starlinkinternet-dish-hack/ 12 KU Leuven-COSIC. 2022. Starlink-FI. https://github.com/KULeuven-COSIC/Starlink-FI 13 Humphreys, T. et al. 2022. Signal Structure of the Starlink Ku-Band Downlink. Cornell University. https://arxiv.org/pdf/2210.11578 14 See DEFCON. https://defcon.org/index.html and the linked article published on The Register: https://www.theregister.com/2023/06/03/moonlighter_satellite_hacking/ 15 Gedeon, J. 2023. For the first time, U.S. government lets hackers break into satellite in space. Politico. https://www.politico.com/news/2023/08/11/def-con-hackers-space-force-00110919 16 Peeters, W. 2023. Cyberattacks on Satellites: An Underestimated Political Threat.LSE. https://www.lse.ac.uk/ideas/projects/space-policy/publications/Cyberattacks-on-Satellites 17 Porras, D. 2023. Shared risks: An examination of universal space security challenges. Briefing paper for the United Nations Disarmament Commission. UNIDIR. https://unidir.org/wp-content/uploads/2023/05/shared-risks-an-examination-ofuniversal-space-security-challenges-en-775.pdf 18 European Commission, 2022. EU Space Strategy for Security and Defence. https://defence-industryspace.ec.europa.eu/eu-space-policy/eu-space-strategy-security-and-defence_en 19 Peeters, W. 2023. Cyberattacks on Satellites: An Underestimated Political Threat. https://www.lse.ac.uk/ideas/projects/space-policy/publications/Cyberattacks-on-Satellites
  3. 20 Peeters, W. 2023. Cyberattacks on Satellites: An Underestimated Political Threat. https://www.lse.ac.uk/ideas/projects/space-policy/publications/Cyberattacks-on-Satellites 21 Peeters, W. 2023. Cyberattacks on Satellites: An Underestimated Political Threat. https://www.lse.ac.uk/ideas/projects/space-policy/publications/Cyberattacks-on-Satellites 22 Peeters, W. 2023. Cyberattacks on Satellites: An Underestimated Political Threat. https://www.lse.ac.uk/ideas/projects/space-policy/publications/Cyberattacks-on-Satellites 23 Khandelwal, S. 2015. Russian Hackers Hijack Satellite To Steal Data from Thousands of Hacked Computers https://thehackernews.com/2015/09/hacking-satellite.html 24 Nelson, N. 2023 How Hackers Can Hijack a Satellite https://www.darkreading.com/cybersecurity-analytics/howresearchers-hijacked-a-satellite
  4. 25 European Commission, 2023. Directive on measures for a high common level of cybersecurity across the Union (NIS2 Directive). https://digital-strategy.ec.europa.eu/en/policies/nis2-directive 26 Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act). http://data.europa.eu/eli/reg/2024/2847/oj 27 ECSS, 2023. ECSS Active Standards. https://ecss.nl/standards/active-standards/ 28 For example, ongoing work on the Space product assurance – Security in space systems lifecycles standard (ECSS-Q- ST-80-10C-DIR1)
  5. 29 CCSDS. July 2022. Space Data Link Security Protocol. CCSDS 355.0-B-2. https://public.ccsds.org/Pubs/355x0b2.pdf 30 Note: CCSDS’ protocols are presented in the form of recommendations and are not legally binding. 31 IEEE. Standard for Space System Cybersecurity. P3349. https://standards.ieee.org/ieee/3349/11182/ 32 UG Government. 2020. Space Policy Directive 5 (SPD-5). https://www.cisa.gov/resources-tools/resources/space-policydirective-5 33 Scholl, M. & Suloway, T. NIST, 2023. Introduction to Cybersecurity for Commercial Satellite Operations. https://nvlpubs.nist.gov/nistpubs/ir/2023/NIST.IR.8270.pdf 34 Space ISAC. https://spaceisac.org/
  6. 35 Specifically, common phases of the standard systems engineering process include the following: Requirements analysis, Specifications, Design, Implementation, Test, and Maintenance, with Feedback as a cross-cutting element. Shiotani. B. 2018. Project Life-Cycle and Implementation for a class of small Satellites. https://s3vi.ndc.nasa.gov/ssrikb/static/resources/SHIOTANI_B.pdf 36 BSI, 2022, IT-Grundschutz Profile for Space Infrastructures. https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Grundschutz/profiles/Profile_Space- Infrastructures.pdf?__blob=publicationFile&v=2 37 Scholl, M. & Suloway, T. NIST, 2023. Introduction to Cybersecurity for Commercial Satellite Operations. https://nvlpubs.nist.gov/nistpubs/ir/2023/NIST.IR.8270.pdf
  7. SpaceX, September 2021. Falcon User’s Guide. https://www.spacex.com/media/falcon-users-guide-2021-09.pdf SpaceX. Rocket Crew list of open positions. https://www.spacex.com/careers/jobs/ Rocket Crew. The biggest list of space jobs and aerospace from new space companies. https://rocketcrew.space/ Moiz, A. Indeed, July 2023. 22 Jobs in the Space Industry To Explore (Plus Duties). https://www.indeed.com/careeradvice/finding-a-job/jobs-in-space-industry NASA. List of featured careers. https://www.nasa.gov/careers/featured-careers
  8. 43 Starlink. SpaceX. https://www.starlink.com/
  9. 44 In the context of a lifecycles of specific satellites, the roles of actors may be combined e.g. mechanical engineer can also conduct tasks delegated here to a test engineer etc.
  10. 45 Note: Production, transportation and launch are also commonly considered as part of satellite operations. They are labelled as separate categories here for ease of understanding the different process.
  11. Willbold, J., Schloegel, M., Vogele, M., Gerhardt, M., Holz, T., Abbasi, A. 2023. Space Odyssey: An Experimental Software Security Analysis of Satellites. In IEEE Symposium on Security and Privacy. https://jwillbold.com/paper/willbold2023spaceodyssey.pdf. Manulis, M. et al. (2020). Cyber security in New Space: Analysis of Threats, Key Enabling Technologies, and Challenges. International Journal of Information Security. https://www.researchgate.net/publication/341331628_Cyber_security_in_New_Space_Analysis_of_threats_key_enabling_t echnologies_and_challenges. BSI. (2023). Technical Guideline BSI TR-03184 Information Security for Space Systems. https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Publications/TechGuidelines/TR03184/BSI-TR- 03184_part1.pdf?__blob=publicationFile&v=2. NIST. 2022. Satellite Ground Segment: Applying the Cybersecurity Framework to Satellite Command and Control. https://nvlpubs.nist.gov/nistpubs/ir/2022/NIST.IR.8401.pdf. BSI, 2022, IT-Grundschutz Profile for Space Infrastructures. https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Grundschutz/profiles/Profile_Space- Infrastructures.pdf?__blob=publicationFile&v=2 ESA, 2020, ESA TECHNOLOGY TREE, Version 4.0. https://esamultimedia.esa.int/multimedia/publications/STM- 277/STM-277.pdf. The Consultative Committee for Space Data Systems. 2023. Space Link Extension – Forward CLTU Service Specification. https://public.ccsds.org/Pubs/912x1b5.pdf Quiquet, F. 2020. Description of the Elements of a Satellite Command and Control System. https://www.spacesecurity.info/en/description-of-the-elements-of-a-satellite-command-and-control-system/
  12. 54, 55, 56, 57, 58, 59 The Space segment contains satellite(s) orbiting the Earth. It can include satellites that are operating independent of other satellites, several satellites orbiting the Earth arranged in a regular pattern (i.e. a satellite constellation), or satellites in completely different orbits but serving the same mission. Categories defined in the Space segment include:
  13. 54 ESA. Science and Exploration: Power. https://www.esa.int/Science_Exploration/Human_and_Robotic_Exploration/Orion/Power 55 Guven, U. Power System Design for Earth Orbiting Satellites. Aerospace Lectures. https://www.aerospacelectures.com/Power%20System%20Design%20for%20Earth-Orbiting%20Satellites.pdf 56 Ear, E., Remy, L.C.J., Feffer, A., Hu, S. 2023. Characterizing Cyber Attacks against Space Systems with Missing Data: Framework and Case Study. https://arxiv.org/pdf/2309.04878.pdf 57 BSI. 2023. Technical Guideline BSI TR-03184 Information Security for Space Systems. https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Publications/TechGuidelines/TR03184/BSI-TR- 03184_part1.pdf?__blob=publicationFile&v=2 58 Scholl, M. Suloway, T. 2023. Introduction to Cybersecurity for Commercial Satellite Operations. https://tsapps.nist.gov/publication/get_pdf.cfm?pub_id=936776 59 Manulis, M. Bridges, C.P., Harrison, R., Sekar, V., Davis, A. 2020. Cyber security in New Space. https://link.springer.com/article/10.1007/s10207-020-00503-w
  14. 62,63 service.
  15. 60 Willbold, J., Schloegel, M., Vogele, M., Gerhardt, M., Holz, T., Abbasi, A. 2023. Space Odyssey: An Experimental Software Security Analysis of Satellites. In IEEE Symposium on Security and Privacy. https://jwillbold.com/paper/willbold2023spaceodyssey.pdf. 61 NIST. 2023. Introduction to Cybersecurity for Commercial Satellite Operations. https://nvlpubs.nist.gov/nistpubs/ir/2023/NIST.IR.8270.pdf. NIST. 2023. Cybersecurity Framework Profile for Hybrid Satellite Networks (HSN). https://nvlpubs.nist.gov/nistpubs/ir/2023/NIST.IR.8441.pdf 63 Quiquet, F. 2020. Description of the Elements of a Satellite Command and Control System. https://www.spacesecurity.info/en/description-of-the-elements-of-a-satellite-command-and-control-system/ 64 Ocean Web. 2022. A guide to maritime VSAT. https://www.oceanweb.com/a-guide-to-maritime-vsat/ 65 Gartner. Very Small Aperture Terminal (VSAT). https://www.gartner.com/en/information-technology/glossary/vsat-verysmall-apertureterminal#:~:text=A%20very%20small%20aperture%20terminal,communication%20network%2C%20excluding%20broadcas t%20television. 66 NIST. 2023. Introduction to Cybersecurity for Commercial Satellite Operations. https://nvlpubs.nist.gov/nistpubs/ir/2023/NIST.IR.8270.pdf
  16. 67 Space Security Community. Space Attacks Open Database Project. https://www.spacesecurity.info/en/space-attacksopen-database/ 68 UNOOSA statistics on the annual number of objects launched into space indicate a 300+% increase of objects launched into space for this timeframe, from less than 600 objects launched in 2019, to over 2500 objects launched in 2023, the majority of these being commercial assets. Online Index of Objects Launched into Outer Space. United Nations Office for Outer Space Affairs. https://www.unoosa.org/oosa/osoindex/index.jspx?lf_id= 69 ENISA. 2023. ENISA Foresight Cybersecurity Threats for 2030. https://www.enisa.europa.eu/publications/enisaforesight-cybersecurity-threats-for-2030
  17. 70 ENISA. 2024. Foresight Cybersecurity Threats For 2030 - Update 2024: Extended report. https://www.enisa.europa.eu/publications/foresight-cybersecurity-threats-for-2030-update-2024-extended-report.
  18. 71 INSPIRE registry: Manufacturing not elsewhere classified (n.e.c.) https://inspire.ec.europa.eu/codelist/EconomicActivityNACEValue/C.32.99 72 EU Space ISAC https://www.euspa.europa.eu/eu-space-programme/eu-space-and-security/eu-space-isac
  19. 73 ENISA. September 2024. ENISA Threat Landscape 2024. https://www.enisa.europa.eu/publications/enisa-threatlandscape-2024 74 ENISA. 2021. Methodology for Sectoral Cybersecurity Assessments. https://www.enisa.europa.eu/publications/methodology-for-a-sectoral-cybersecurity-assessment
  20. Baram, G. and Wechsler, O. 2020. Cyber Threats to Space Systems. Current Risks and the Role of NATO. Joint Air Power Competence Centre. https://www.japcc.org/essays/cyber-threats-to-space-systems/ Bichler, S. F. 2015. Mitigating Cyber Security Risk in Satellite Ground Systems. Air Command and Staff College. https://apps.dtic.mil/sti/pdfs/AD1012754.pdf Garino, B. and Gibson, J. 2018. Space System Threats. Aerospace Security. https://aerospace.csis.org/wpcontent/uploads/2018/09/Space-System-Threats.pdf Manulis, M. et al. (2020). Cyber security in New Space: Analysis of Threats, Key Enabling Technologies, and Challenges. International Journal of Information Security. https://www.researchgate.net/publication/341331628_Cyber_security_in_New_Space_Analysis_of_threats_key_enabling_t echnologies_and_challenges Matei, V.C. 2021. Cybersecurity Analysis for the Internet-Connected Satellites. Uppsala Universitet. https://uu.divaportal.org/smash/get/diva2:1622956/FULLTEXT01.pdf Livingstone, D. and Lewis, P. 2016. Space, the Final Frontier for Cybersecurity? Chatham House. https://www.chathamhouse.org/sites/default/files/publications/research/2016-09-22-space-final-frontier-cybersecuritylivingstone-lewis.pdf Varadharajan, V. and Suri, N. 2022. Security Challenges when Space Merges with Cyberspace. Cornell University. https://arxiv.org/pdf/2207.10798 Willbold, J., Schloegel, M., Vogele, M., Gerhardt, M., Holz, T., Abbasi, A. 2023. Space Odyssey: An Experimental Software Security Analysis of Satellites. In IEEE Symposium on Security and Privacy. https://jwillbold.com/paper/willbold2023spaceodyssey.pdf Aerospace Corporation. Space Attack Research & Tactic Analysis (SPARTA). https://sparta.aerospace.org/ Bailey, B. et al. 2019. Defending Spacecraft in the Cyber Domain. Center for Space Policy and Strategy. https://aerospace.org/sites/default/files/2019-11/Bailey_DefendingSpacecraft_11052019.pdf Bailey, B. 2020. Establishing Space Cybersecurity Policy, Standards, and Risk Management Practices. Aerospace Corporation. https://aerospace.org/sites/default/files/2020-10/Bailey%20SPD5_20201010%20V2_formatted.pdf BSI. (2023). Technical Guideline BSI TR-03184 Information Security for Space Systems. https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Publications/TechGuidelines/TR03184/BSI-TR- 03184_part1.pdf?__blob=publicationFile&v=2. The Consultative Committee for Space Data Systems. 2022. Security Threats Against Space Missions. CCSDS 350.1-G- 3. https://public.ccsds.org/Pubs/350x1g3.pdf Bingen, K. Johnson, K. and Young, M. 2023. Space Threat Assessment 2023. Center for Strategic & International Studies. https://csis-website-prod.s3.amazonaws.com/s3fs-public/2023- 04/230414_Bingen_Space_Assessment.pdf?VersionId=oMsUS8MupLbZi3BISPrqPCKd5jDejZnJ ESPI. 2022. ESPI Report 84 - The war in Ukraine from a space cybersecurity perspective. https://www.espi.or.at/wpcontent/uploads/2022/10/ESPI-Report-84.pdf Fortinet. August 2022. Global Threat Landscape Report. A Semiannual Report by FortiGuard Labs. https://www.fortinet.com/content/dam/fortinet/assets/threat-reports/threat-report-1h-2022.pdf Scholl, M. & Suloway, T. NIST, 2023. Introduction to Cybersecurity for Commercial Satellite Operations. https://nvlpubs.nist.gov/nistpubs/ir/2023/NIST.IR.8270.pdf UK Space Agency. 2020. Cyber Security Toolkit. https://assets.publishing.service.gov.uk/media/5ec298a3e90e071e2f955ebc/Space_cyber_toolkit_final_v4.pdf White House. 2020. Memorandum on Space Policy Directive-5 – Cybersecurity Principles for Space Systems. https://trumpwhitehouse.archives.gov/presidential-actions/memorandum-space-policy-directive-5-cybersecurity-principlesspace-systems/ ENISA. 2021. Methodology for Sectoral Cybersecurity Assessments. https://www.enisa.europa.eu/publications/methodology-for-a-sectoral-cybersecurity-assessment
  21. 95 ENISA. 2016. ENISA Threat Taxonomy. https://www.enisa.europa.eu/topics/cyber-threats/threats-and-trends/enisathreat-landscape/threat-taxonomy/view 96 ESPI. 2022. ESPI Report 84 - The war in Ukraine from a space cybersecurity perspective. https://www.espi.or.at/wpcontent/uploads/2022/10/ESPI-Report-84.pdf 97 Willbold, J., Schloegel, M., Vogele, M., Gerhardt, M., Holz, T., Abbasi, A. 2023. Space Odyssey: An Experimental Software Security Analysis of Satellites. In IEEE Symposium on Security and Privacy. https://jwillbold.com/paper/willbold2023spaceodyssey.pdf 98 Manulis, M. et al. (2020). Cyber security in New Space: Analysis of Threats, Key Enabling Technologies, and Challenges. International Journal of Information Security. https://www.researchgate.net/publication/341331628_Cyber_security_in_New_Space_Analysis_of_threats_key_enabling_t echnologies_and_challenges. 99 Peeters, W. 2022. Cyberattacks on Satellites: An Underestimated Political Threat. LSE Ideas. https://www.lse.ac.uk/ideas/projects/space-policy/publications/Cyberattacks-on-Satellites 100 Manulis, M. et al. (2020). Cyber security in New Space: Analysis of Threats, Key Enabling Technologies, and Challenges. International Journal of Information Security. https://www.researchgate.net/publication/341331628_Cyber_security_in_New_Space_Analysis_of_threats_key_enabling_t echnologies_and_challenges. 101 Aerospace Corporation. Space Attack Research & Tactic Analysis (SPARTA). https://sparta.aerospace.org/
  22. 102 European Space Agency. Space Attacks and Countermeasures Engineering Shield (SPACE-SHIELD). https://spaceshield.esa.int/ 103 For a detailed assessment of Low Earth Orbit (LEO) constellations, commonly used in the current space setup in Europe, please refer to ENISA’s targeted report on LEOs. ENISA, 2024. Low Earth Orbit (LEO) SATCOM Cybersecurity Assessment. https://www.enisa.europa.eu/publications/low-earth-orbit-leo-satcom-cybersecurity-assessment
  23. 104 The risk scenarios provide a limited sample of possible attack technique chains. For more information, research conducted by Department of Computer Science at the University of Colorado can be consulted, which identified 72 attack tactic chains and 4,076 attack technique chains. Ear, E., Remy, L.C.J., Feffer, A., Hu, S. 2023. Characterizing Cyber Attacks against Space Systems with Missing Data: Framework and Case Study. https://arxiv.org/pdf/2309.04878.pdf 105 For additional guidance, the ISO 31000 Risk management standard can be used.
  24. 106 SatNOGS Open Source global network of satellite ground-stations. https://satnogs.org/
  25. Namely, Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union (NIS 2 Directive). International Organisation for Standardisation (ISO), 2022. ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection — Information security management systems — Requirements. National Institute of Standards and Technology (NIST), 2024. The NIST Cybersecurity Framework (CSF) 2.0. https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf Scholl, M. and Suloway, T. 2023. Introduction to Cybersecurity for Commercial Satellite Operations. NIST. NIST IR 8270. https://csrc.nist.gov/pubs/ir/8270/final Bartock, M. et al. 2023. Foundational PNT Profile: Applying the Cybersecurity Framework for the Responsible Use of Positioning, Navigation, and Timing (PNT) Services. NIST. NIST IR 8323 Rev. 1. https://csrc.nist.gov/pubs/ir/8323/r1/final Lightman, S. Suloway, T. and Brule, J. 2022. Satellite Ground Segment - Applying the Cybersecurity Framework to Satellite Command and Control. NIST. NIST IR 8401. https://csrc.nist.gov/pubs/ir/8401/final McCarthy, J. et al. 2023. Cybersecurity Framework Profile for Hybrid Satellite Networks (HSN). NIST. NIST IR 8441. https://nvlpubs.nist.gov/nistpubs/ir/2023/NIST.IR.8441.ipd.pdf National Aeronautics and Space Administration (NASA), 2024. Space Security: Best Practice Guide (BPG). https://swehb.nasa.gov/display/SWEHBVD/7.22+-+Space+Security%3A+Best+Practices+Guide Aerospace Corporation. Space Attack Research & Tactic Analysis (SPARTA). SPARTA Countermeasures. https://sparta.aerospace.org/countermeasures/SPARTA Federal Office for Information Security (BSI), 2022. IT-Grundschutz Profile for Space Infrastructures: Minimum Protection for Satellites Covering their Entire Life Cycle. https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Grundschutz/profiles/Profile_Space- Infrastructures.pdf?__blob=publicationFile&v=2 Federal Office for Information Security (BSI), 2023. Technical Guideline BSI TR-03184 Information Security for Space Systems - Part 1: Space segment Ministry of Economy, Trade and Industry (METI) Cybersecurity Guidelines for Commercial Space Systems
  26. 119 Software and protocol updates, especially when distributed across multiple ground stations, require robust integrity checks. The update process and its management are critical, particularly when multiple ground stations are involved, to ensure continuity even while the satellite is in orbit. Update protocols must guarantee the integrity of the software update after the consolidation of all received packets. Update protocol resilience in the presence of untrusted Ground Stations is especially important as missions might rely on open networks (e.g. SatNOGS) that rely on voluntary contributions, raising significant concerns about the level of trust that can be placed in such diverse and potentially unverified ground stations. 120 Integrity checks are crucial for maintaining satellite operational integrity. This includes secure boot mechanisms to ensure the correct image is loaded at each startup. Furthermore, vetted backup operational images and a robust recovery process are essential to mitigate the impact of failures (whether due to malicious actions or natural events like geomagnetic storms) and prevent the satellite from becoming inoperable.
  27. The Consultative Committee for Space Data Systems (CCSDS) has established a Space Link Extension (SLE) which is a standardized set of services that allow control centres to connect to the ground antenna sites and to send satellite data back and forth.
  28. SOaaS - Satellite Operations as a Service. https://connectivity.esa.int/projects/soaas