Solar Energy News
SPACEWAR
Satellite security lags decades behind the state of the art
The examined satellites were two small models and one medium-sized model - research satellites as well as a satellite of a commercial company - which orbit the Earth at a short distance and are used to observe the Earth. Gaining access to satellites and their software was a challenge for the team, as commercial providers in particular rarely wish to reveal any details. The researchers eventually gained access through cooperation with the European Space Agency (ESA), various universities involved in the construction of satellites, and a commercial enterprise.
Satellite security lags decades behind the state of the art
by Staff Writers
Bochum, Germany (SPX) Jul 12, 2023

Thousands of satellites are currently orbiting the Earth, and there will be many more in the future. Researchers from Ruhr University Bochum and the CISPA Helmholtz Center for Information Security in Saarbrucken have assessed the security of these systems from an IT perspective. They analysed three current low-earth orbit satellites and found that, from a technical point of view, hardly any modern security concepts were implemented. Various security mechanisms that are standard in modern mobile phones and laptops were not to be found: for example, there was no separation of code and data. Interviews with satellite developers also revealed that the industry relies primarily on security through obscurity.

The results were presented by a team headed by Johannes Willbold, a PhD student from Bochum, Dr. Ali Abbasi, a researcher from Saarbrucken, and Professor Thorsten Holz, formerly in Bochum, now in Saarbrucken, at the IEEE Symposium on Security and Privacy, which took place in San Francisco from 22 to 25 May 2023. The paper was awarded a Distinguished Paper Award at the conference.

Research satellites and commercial satellite put to the test
The examined satellites were two small models and one medium-sized model - research satellites as well as a satellite of a commercial company - which orbit the Earth at a short distance and are used to observe the Earth. Gaining access to satellites and their software was a challenge for the team, as commercial providers in particular rarely wish to reveal any details. The researchers eventually gained access through cooperation with the European Space Agency (ESA), various universities involved in the construction of satellites, and a commercial enterprise.

The team from Bochum and Saarbrucken conducted a thorough security analysis of the three models. They looked in detail at what the software running on the devices does and which communication protocols are used. They emulated the systems, i.e., rebuilt them virtually, so that they could test the software as if it were in a real satellite. "It was a very different world from the systems we usually study. For example, completely different communication protocols were used," as Thorsten Holz outlines the process.

Systems with specific requirements
Satellites orbiting the Earth can only be reached by their ground station on Earth within a time window of a few minutes. The systems must be robust against the radiation in space, and, since they can only consume a small amount of energy, they have a low power output. "The data rates are like those of modems in the 1990s," as Holz elaborates the challenges satellite developers face.

Based on the findings gained from the software analysis, the researchers worked out various attack scenarios. They showed that they could cut off the satellites from ground control and seize control of the systems, for example in order to take pictures with the satellite camera. "We were surprised that the technical security level is so low," points out Thorsten Holz, adding the following caveat with regard to potential ramifications: "It wouldn't be all that easy to steer the satellite to another location, for example, to crash it or have it collide with other objects."

Survey among developers
To find out how the people who develop and build satellites approach security, the research team compiled a questionnaire and submitted it to research institutions, the ESA, the German Aerospace Centre and various enterprises. Nineteen developers participated anonymously in the survey. "The results show us that the understanding of security in the industry is different than in many other areas, specifically that it's security by obscurity," concludes Johannes Willbold. Many of the respondents therefore assumed that satellites could not be attacked because there is no documentation of the systems, i.e., nothing is known about them. Only a few said that they encrypt data when communicating with satellites or use authentication in order to ensure that only the ground station is allowed to communicate with the satellite.

"However, a lack of documentation doesn't necessarily protect against attacks," points out Moritz Schloegel, co-author of the paper. "Today, systems can be figured out through reverse engineering and their vulnerabilities can be identified. One of the goals of our project was therefore to bring the satellite and security communities together to promote a mutual understanding of the challenges of space applications and of the security standards that are in use today."

Research Report:Space odyssey: An experimental software security analysis of satellites

Related Links
Ruhr-University Bochum
Military Space News at SpaceWar.com

Subscribe Free To Our Daily Newsletters
Tweet

RELATED CONTENT
The following news reports may link to other Space Media Network websites.
SPACEWAR
Space Force, Air Force sign MOA on Guardian uniform development
Arlington VA (SPX) Jul 12, 2023
Department of the Air Force senior executives signed a memorandum of agreement continuing the development of U.S. Space Force uniforms to accommodate all genders, life events and weather conditions July 11. Wade Yamada, deputy director of staff, Office of the Chief of Space Operations, and Lea Kirkwood, program executive officer and director, Air Force Life Cycle Management Center's Agile Combat Support Directorate, signed the MOA extending an agreement signed May 16, 2022. The memo of understandi ... read more

SPACEWAR
University of Illinois study finds turning food waste into bioenergy can become a profitable industry

New technology will let farmers produce their own fertilizer and e-fuels

Clean, sustainable fuels made 'from thin air' and plastic waste

In Iowa, Asa Hutchinson touts measured approach to green energy transition

SPACEWAR
Musk launches xAI to rival OpenAI, Google

NASA humanoid robot to be tested in Australia

Google launches ChatGPT rival Bard in EU, Brazil

Google launches ChatGPT rival Bard in EU, Brazil

SPACEWAR
New transmission line to carry wind energy electricity from Wyoming to Nevada

Brazil faces dilemma: endangered macaw vs. wind farm

Spire to provide TrueOcean with weather forecasts for offshore wind farm development

Sweden greenlights two offshore windpower farms

SPACEWAR
Thermal cloak passively keeps electric vehicles cool in the summer and warm in the winter

Malaysia PM holds virtual talks with Musk on Tesla investment

Musk predicts Tesla self-driving cars 'later this year'

Legal battle looms over London's expanding vehicle pollution fee

SPACEWAR
Next-generation flow battery design sets records

A bright future in eco-friendly light devices, just add dendrimers, cellulose, and graphene

Scientists developing way to make cheaper Lithium batteries

China, Russia pledge $1.4 bn for lithium plants in Bolivia

SPACEWAR
Uranium Energy Corp completes Restart Program at the Christensen Ranch ISR Project in Wyoming

OpenAI's Sam Altman takes nuclear startup public

IAEA requests more access to Zaporizhzhia nuclear plant in hunt for explosives

Fukushima water release plan clears last regulatory hurdle in Japan

SPACEWAR
The pace of the energy transition is fast, but not fast enough, the IEA says

'Not there yet': COP host UAE vows to cut more emissions

End of S.Africa's blackouts 'within horizon': minister

International Maritime Organization nations agree to 2050 net zero emissions goal

SPACEWAR
Forest can adapt to climate change, but not quickly enough

Sri Lanka uproots 'last legume' tree to build highway

Amazon neighbors act to save world's largest rainforest; Lula slashes Amazon deforestation

Amazon deforestation down sharply under Brazil's Lula: govt

Subscribe Free To Our Daily Newsletters




The content herein, unless otherwise known to be public domain, are Copyright 1995-2024 - Space Media Network. All websites are published in Australia and are solely subject to Australian law and governed by Fair Use principals for news reporting and research purposes. AFP, UPI and IANS news wire stories are copyright Agence France-Presse, United Press International and Indo-Asia News Service. ESA news reports are copyright European Space Agency. All NASA sourced material is public domain. Additional copyrights may apply in whole or part to other bona fide parties. All articles labeled "by Staff Writers" include reports supplied to Space Media Network by industry news wires, PR agencies, corporate press officers and the like. Such articles are individually curated and edited by Space Media Network staff on the basis of the report's information value to our industry and professional readership. Advertising does not imply endorsement, agreement or approval of any opinions, statements or information provided by Space Media Network on any Web page published or hosted by Space Media Network. General Data Protection Regulation (GDPR) Statement Our advertisers use various cookies and the like to deliver the best ad banner available at one time. All network advertising suppliers have GDPR policies (Legitimate Interest) that conform with EU regulations for data collection. By using our websites you consent to cookie based advertising. If you do not agree with this then you must stop using the websites from May 25, 2018. Privacy Statement. Additional information can be found here at About Us.