Military Space News
SPACEWAR
Satellite security lags decades behind the state of the art
The examined satellites were two small models and one medium-sized model - research satellites as well as a satellite of a commercial company - which orbit the Earth at a short distance and are used to observe the Earth. Gaining access to satellites and their software was a challenge for the team, as commercial providers in particular rarely wish to reveal any details. The researchers eventually gained access through cooperation with the European Space Agency (ESA), various universities involved in the construction of satellites, and a commercial enterprise.
Satellite security lags decades behind the state of the art
by Staff Writers
Bochum, Germany (SPX) Jul 12, 2023

Thousands of satellites are currently orbiting the Earth, and there will be many more in the future. Researchers from Ruhr University Bochum and the CISPA Helmholtz Center for Information Security in Saarbrucken have assessed the security of these systems from an IT perspective. They analysed three current low-earth orbit satellites and found that, from a technical point of view, hardly any modern security concepts were implemented. Various security mechanisms that are standard in modern mobile phones and laptops were not to be found: for example, there was no separation of code and data. Interviews with satellite developers also revealed that the industry relies primarily on security through obscurity.

The results were presented by a team headed by Johannes Willbold, a PhD student from Bochum, Dr. Ali Abbasi, a researcher from Saarbrucken, and Professor Thorsten Holz, formerly in Bochum, now in Saarbrucken, at the IEEE Symposium on Security and Privacy, which took place in San Francisco from 22 to 25 May 2023. The paper was awarded a Distinguished Paper Award at the conference.

Research satellites and commercial satellite put to the test
The examined satellites were two small models and one medium-sized model - research satellites as well as a satellite of a commercial company - which orbit the Earth at a short distance and are used to observe the Earth. Gaining access to satellites and their software was a challenge for the team, as commercial providers in particular rarely wish to reveal any details. The researchers eventually gained access through cooperation with the European Space Agency (ESA), various universities involved in the construction of satellites, and a commercial enterprise.

The team from Bochum and Saarbrucken conducted a thorough security analysis of the three models. They looked in detail at what the software running on the devices does and which communication protocols are used. They emulated the systems, i.e., rebuilt them virtually, so that they could test the software as if it were in a real satellite. "It was a very different world from the systems we usually study. For example, completely different communication protocols were used," as Thorsten Holz outlines the process.

Systems with specific requirements
Satellites orbiting the Earth can only be reached by their ground station on Earth within a time window of a few minutes. The systems must be robust against the radiation in space, and, since they can only consume a small amount of energy, they have a low power output. "The data rates are like those of modems in the 1990s," as Holz elaborates the challenges satellite developers face.

Based on the findings gained from the software analysis, the researchers worked out various attack scenarios. They showed that they could cut off the satellites from ground control and seize control of the systems, for example in order to take pictures with the satellite camera. "We were surprised that the technical security level is so low," points out Thorsten Holz, adding the following caveat with regard to potential ramifications: "It wouldn't be all that easy to steer the satellite to another location, for example, to crash it or have it collide with other objects."

Survey among developers
To find out how the people who develop and build satellites approach security, the research team compiled a questionnaire and submitted it to research institutions, the ESA, the German Aerospace Centre and various enterprises. Nineteen developers participated anonymously in the survey. "The results show us that the understanding of security in the industry is different than in many other areas, specifically that it's security by obscurity," concludes Johannes Willbold. Many of the respondents therefore assumed that satellites could not be attacked because there is no documentation of the systems, i.e., nothing is known about them. Only a few said that they encrypt data when communicating with satellites or use authentication in order to ensure that only the ground station is allowed to communicate with the satellite.

"However, a lack of documentation doesn't necessarily protect against attacks," points out Moritz Schloegel, co-author of the paper. "Today, systems can be figured out through reverse engineering and their vulnerabilities can be identified. One of the goals of our project was therefore to bring the satellite and security communities together to promote a mutual understanding of the challenges of space applications and of the security standards that are in use today."

Research Report:Space odyssey: An experimental software security analysis of satellites

Related Links
Ruhr-University Bochum
Military Space News at SpaceWar.com

Subscribe Free To Our Daily Newsletters
Tweet

RELATED CONTENT
The following news reports may link to other Space Media Network websites.
SPACEWAR
Space Force, Air Force sign MOA on Guardian uniform development
Arlington VA (SPX) Jul 12, 2023
Department of the Air Force senior executives signed a memorandum of agreement continuing the development of U.S. Space Force uniforms to accommodate all genders, life events and weather conditions July 11. Wade Yamada, deputy director of staff, Office of the Chief of Space Operations, and Lea Kirkwood, program executive officer and director, Air Force Life Cycle Management Center's Agile Combat Support Directorate, signed the MOA extending an agreement signed May 16, 2022. The memo of understandi ... read more

SPACEWAR
Lockheed Martin achieves milestone in PAC-3 MSE Integration with Aegis Weapon System

Swiss want in on Germany's Sky Shield plan

Lockheed Martin targets small businesses via Next Generation Interceptor

Poland to buy US Patriot missile defense systems worth $15 bn

SPACEWAR
Millennium Space Systems Missile Track Custody PDR complete in just four months

First French long-range missiles already in Ukraine

France to send Ukraine SCALP long-range missiles: Macron

France's SCALP missiles: long-range weapon for Ukraine's armoury

SPACEWAR
Pentagon calls on Russia to stop 'reckless behavior' in Syria

U.S. kills ISIS leader in Syria with drones that had been harassed by Russia

CENTCOM: Russian jets harassed U.S. drones in Syria

Drones steal the spotlight at Paris Air Show

SPACEWAR
ATLAS Space launches Freedom Space for Government Missions

SYRACUSE 4B Satellite Launched: Boost for French Military Communications

DoD awards Global X-Band Blanket Purchase Agreement to SES

Ensuring reliable communications between US and Partners at the tactical edge

SPACEWAR
US military pinned down by Republican fire on 'wokeness'

US cluster munitions delivered to Ukraine

RTX secures $117M contract with US Army for Advanced Targeting Sensor Systems

Fury among aid groups as US approves cluster bombs for Ukraine

SPACEWAR
UK minister warns West 'not Amazon' for Ukraine weapons

Germany pledges 700 mn euros in new arms aid to Ukraine

Biden thanks Erdogan for Sweden decision, backs F-16s sale

Cuba, Russia envisage technical-military cooperation

SPACEWAR
Big power disputes in spotlight at Southeast Asia security meet

Zelensky hails 'security victory' after G7 vow support

Biden had to be an Erdogan whisperer. But then came Zelensky

Turkey will not ratify Sweden's NATO bid before October: Erdogan

SPACEWAR
Single-molecule valve: a breakthrough in nanoscale control

Subscribe Free To Our Daily Newsletters




The content herein, unless otherwise known to be public domain, are Copyright 1995-2024 - Space Media Network. All websites are published in Australia and are solely subject to Australian law and governed by Fair Use principals for news reporting and research purposes. AFP, UPI and IANS news wire stories are copyright Agence France-Presse, United Press International and Indo-Asia News Service. ESA news reports are copyright European Space Agency. All NASA sourced material is public domain. Additional copyrights may apply in whole or part to other bona fide parties. All articles labeled "by Staff Writers" include reports supplied to Space Media Network by industry news wires, PR agencies, corporate press officers and the like. Such articles are individually curated and edited by Space Media Network staff on the basis of the report's information value to our industry and professional readership. Advertising does not imply endorsement, agreement or approval of any opinions, statements or information provided by Space Media Network on any Web page published or hosted by Space Media Network. General Data Protection Regulation (GDPR) Statement Our advertisers use various cookies and the like to deliver the best ad banner available at one time. All network advertising suppliers have GDPR policies (Legitimate Interest) that conform with EU regulations for data collection. By using our websites you consent to cookie based advertising. If you do not agree with this then you must stop using the websites from May 25, 2018. Privacy Statement. Additional information can be found here at About Us.