Publication: enisa-stl-2025-03 Space Threat Landscape
Full text
The control text is third-party content; see the official source for the full wording.
Mapped SPARTA techniques
31 techniques
Integrity-checking on flight code surfaces patches and bypasses to FDIR routines that DE-0001 introduces.
Integrity checking covering proper management of information and records detects modification of housekeeping fields, counters, and mode indicators.
Integrity checking validates baselined mission software, programmable logic, and firmware and is relevant to the integrity domain, but the Vehicle Command Counter is a live runtime telemetry value outside the signed baseline, so the excerpt does not show active detection of runtime VCC manipulation.
Integrity checking covering proper management of information and records detects modification of executed-command histories and file records.
Integrity checking on watchdog configuration values detects unauthorised tampering used to extend or disable timeouts.
Integrity checking on training corpora and packaged ML model artefacts detects poisoned data before deployment.
Integrity checking on whitelist configuration data detects unauthorised modifications attempting to add malicious software.
Integrity checking on flight software detects rootkit-installed API/syscall hooks and patched message queues that bias telemetry before downlink.
Integrity checking covering pre-OS boot artefacts directly defeats bootkit shaping of what subsequent components observe.
Integrity-checking mechanisms on mission software and firmware detect modification of authentication code paths and gateway processors.
Integrity-checking mechanisms covering programmable logic and firmware images directly defeat modifications to boot ROMs, bootloaders, and OTP fuses.
Integrity checks on firmware, bitstreams, and programmable-logic images detect corruption of trust anchors below the application stack.
Integrity checking surfaces substitution of crypto libraries or tables during boot or update — one EX-0006 path.
Integrity checks (ECC, software/firmware validation) detect transient bit flips that EX-0007 attempts to convert into persistent compromise.
Integrity-checking mechanisms across mission software, programmable logic, and firmware detect injected binaries, hooks, and modified images.
Integrity-checking mechanisms detect rootkit-induced kernel hooks, syscall patches, and modified message queues by comparing against signed baselines.
Integrity checks across mission software and firmware including pre-OS boot artefacts directly defeat bootkit substitution of boot images and image-selection logic.
Integrity checking on mission software and firmware extends to the live and persistent data structures EX-0012 modifies (registers, tables, schedules, autonomy rules).
Integrity checking validates the integrity of baselined mission software, programmable logic, and firmware, which is relevant to the integrity domain EX-0012.01 attacks, but internal registers hold live runtime values outside the signed baseline, so the excerpt does not show active detection of runtime register modification.
Integrity-checking mechanisms validate mission software and firmware, the targets of memory write/load operations EX-0012.03 issues.
Integrity checking on tables and configuration data detects unauthorised modifications to subscriber lists.
Integrity checks on payload and science data products detect modification of the values EX-0012.06 alters in storage.
Integrity-checking surfaces unauthorised modifications to watchdog timer values that EX-0012.11 issues.
Integrity checking on training datasets and packaged model artefacts detects unauthorised modifications before models are deployed.
Integrity checking on programmable logic and firmware including SDR DSP chains, FEC framing, and routing tables surfaces unauthorised modifications to communications configuration.
Integrity checking on programmable logic devices including SDR bitstreams and DSP modules detects covert-channel injections that EXF-0006.01 packages as legitimate updates.
Integrity checking on regenerative-payload routing tables and QoS rules detects edits that mirror traffic to unauthorised endpoints.
Integrity-checking mechanisms validate mission software, programmable-logic, and firmware images, the artefacts IA-0007.01 substitutes.
Integrity checking surfaces telemetry-value modifications and falsified evidence that IMP-0001 introduces.
Integrity-checking on mission software and firmware including non-volatile images, fallback partitions, and configuration words detects persistent payload reinjection across resets.
Integrity checking detects backdoors introduced through unauthorised modifications to flight binaries during integration or on-orbit updates.