Publication: enisa-stl-2025-03 Space Threat Landscape
Full text
The control text is third-party content; see the official source for the full wording.
Mapped SPARTA techniques
11 techniques
Software/firmware updates with regression testing close the corruption windows EX-0005 leverages once vulnerabilities are identified.
Software updates with regression testing close exploitable software defects, including known issues in commercial components EX-0009 targets.
OS software updates with regression testing close kernel-level defects exposed in maintenance builds before they reach EX-0009.02 exploitation.
Software updates that incorporate security-relevant fixes close the matched-build/known-CVE windows EX-0009.03 exploits.
Restoration to gold images per the software-updates procedure is the canonical defense against wiper-induced executable-image destruction.
Regularly performed, regression-tested software updates govern the SDR software baseline and are relevant to its integrity, but regression testing validates function rather than detecting the covert DSP-chain or FEC modifications EXF-0006.01 uses.
A regularly performed, regression-tested update process governs the legitimate update path IA-0001.02 abuses, but regression testing validates function rather than detecting malicious patches, so this is domain relevance rather than active mitigation.
A regularly performed, regression-tested update process governs the SDR software and bitstream baseline, but regression testing validates function rather than detecting the malicious waveform or bitstream manipulation IA-0002 uses, so addresses rather than mitigates.
Software-update procedures with regression testing cover the on-orbit update pipeline IA-0007.01 manipulates between source and transmission.
Regular software updates close vulnerabilities and reduce the operational value of an adversary-obtained exploit, but updating the victim system does not prevent the resource-development acquisition of exploits, so this is relevance rather than active mitigation of the technique.
Regular software updates close the window in which a catalogued vulnerability is exploitable and reduce the value of REC-0008.03 catalog, but patching the victim does not prevent the reconnaissance activity itself, so addresses rather than mitigates.