arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

星载卫星系统中使用的开源软件的经验性安全分析

An Empirical Security Analysis of Open-Source Software Used in Onboard Satellite Systems

Roee Idan, Tomer Cohen Galor, Asaf Shabtai, Yuval Elovici

arXiv 2609.15425首次发表:更新:

发表机构

Ben-Gurion University of the Negev(内盖夫本-古里安大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本研究通过分析126个开源星载卫星软件仓库,识别出2827项安全发现,其中内存安全与代码质量问题突出,为开源卫星软件生态的安全改进提供了实证依据。

AI 中文摘要

随着任务采用可重用框架、共享库和社区维护组件,卫星飞行系统中开源软件(OSS)的使用日益增多。虽然这加速了开发进程,但也将软件安全风险引入了补丁成本高昂且故障可能影响任务运行的系统。本文对星载卫星系统中使用的开源软件进行了经验性安全研究。我们使用一个结合了软件物料清单生成、软件成分分析、静态应用安全测试、基础设施即代码分析和秘密扫描的流水线,分析了126个公共仓库。经过基于规则的清理、星载范围过滤和基于指纹的去重后,该流水线生成了包含2,827项发现的最终数据集。结果表明,安全发现普遍存在但分布不均。中等严重性发现占数据集的49%,72%的发现被归类为中等严重性或更高。基于常见弱点枚举(CWE)的分类法将所有发现归入八个弱点家族。内存安全性和代码质量在数据集中占主导地位,其次是输入验证和注入。大多数发现出现在项目开发的代码中,占数据集的81.4%,而外部依赖代码仍然是发现的相关来源。虽然这些发现并未确定特定任务的可利用性,但它们提供了对开源星载卫星软件生态系统中反复出现的安全模式的经验性描述,有助于量化其普遍性并优先考虑最需要安全关注的领域。

英文摘要

The use of open-source software (OSS) in satellite flight systems is increasing as missions adopt reusable frameworks, shared libraries, and community-maintained components. While this accelerates development, it also introduces software-security risks into systems where patching is costly and failures may affect mission operations. This paper presents an empirical security study of OSS used in onboard satellite systems. We analyze 126 public repositories using a pipeline that combines software bill of materials generation, software composition analysis, static application security testing, infrastructure-as-code analysis, and secret scanning. After rule-based cleaning, onboard-scope filtering, and fingerprint-based deduplication, the pipeline produced a final dataset of 2,827 findings. The results show that security findings are widespread but unevenly distributed. Medium-severity findings account for 49% of the dataset, and 72% are classified as medium severity or higher. A Common Weakness Enumeration (CWE)-based taxonomy assigns all findings to eight weakness families. Memory Safety and Code Quality dominate the dataset, followed by Input Validation and Injection. Most findings occur in project-developed code, accounting for 81.4% of the dataset, while external dependency code remains a relevant source of findings. While these findings do not establish mission-specific exploitability, they provide an empirical characterization of recurring security patterns across the open-source onboard satellite software ecosystem, helping quantify their prevalence and prioritize areas that warrant the greatest security attention.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑