发表机构
CISPA - Helmholtz Center for Information Security; Cyber-Defence Campus, armasuisse Science + Technology; University of Hamburg(CISPA 赫尔姆霍兹信息安全中心; armasuisse 科学与技术网络防御校园; 汉堡大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对小型卫星中广泛使用的商业现货通信模块,构建威胁分类法并分析多家供应商产品,发现固件、协议和架构中的严重漏洞,通过遥测数据推断至少28个在轨任务易受攻击,揭示通信子系统是危险且被忽视的攻击面。
AI 中文摘要
发射和制造成本的大幅降低导致小型卫星任务的加速部署,商业现货(COTS)组件已成为特定子系统的普遍标准。然而,这种模块化架构引入了关键的安全风险,尤其是在通信子系统(COM)中,该子系统因设计而持续暴露,并被隐式地视为指挥与控制(C2)的入口点。我们针对攻击COM子系统的威胁构建了定制的威胁分类法,并分析了来自不同供应商的代表性COM系统。我们的发现揭示了固件、协议和架构设计中的严重漏洞。这项工作首次对小型卫星中广泛部署的COTS COM模块进行了深入的安全评估,识别出影响数十个任务的漏洞。为了评估现实世界的影响,我们将我们的发现与开源遥测数据相关联,推断出至少28个在轨易受攻击的任务可能遭受恶意接管。我们的工作表明,卫星COM子系统构成了一个有吸引力且被危险忽视的攻击面,亟需社区的紧急关注。
英文摘要
Substantial reduction in launch and manufacturing costs has resulted in the accelerated deployment of small satellite missions, with commercial off-the-shelf (COTS) components becoming the prevailing standard for specific subsystems. However, this modular architecture introduces critical security risks, most notably in the Communication Subsystem (COM), which is continuously exposed by design and implicitly trusted as the entry point for command and control. We construct a tailored threat taxonomy for attacks targeting the COM subsystem and analyze representative COM systems from various vendors. Our findings uncover severe vulnerabilities across firmware, protocols, and architectural designs. This work presents the first in-depth security evaluation of widely deployed COTS COM modules employed in small satellites, identifying vulnerabilities affecting dozens of missions. To assess the real-world impact, we correlate our discoveries with open-source telemetry data, inferring at least 28 vulnerable missions in orbit that are susceptible to hostile takeover. Our work reveals that satellite COM subsystems form an attractive and dangerously neglected attack surface, necessitating urgent attention from the community.
CommentsAccepted at IEEE S&P 2026
DOI:10.1109/SP63933.2026.00213