Publication: enisa-stl-2025-03 Space Threat Landscape
Full text
The control text is third-party content; see the official source for the full wording.
Mapped SPARTA techniques
19 techniques
Cryptographic bidirectional authentication on every command session denies masqueraded origins acceptance, regardless of how authentic the framing appears.
Authentication on every commanding session is uniformly enforced regardless of safe-mode state.
Cryptographic command authentication with bidirectional auth and counters causes replayed command PDUs to fail validation.
Authentication on every command session — including during contingency dictionaries — denies the safe-mode-broader-acceptance pattern EX-0011 relies on.
Authentication of users, devices, and assets — including bus-level authentication — ensures forged inputs cannot pass through normal processing chains.
Bidirectional cryptographic command authentication forces replayed commands to fail validation regardless of how authentic the framing appears.
Cryptographic bidirectional command authentication governs the uplink and limits reuse of captured authentication exchanges, but authentication does not provide the confidentiality that would counter passive collection of uplink command content, so addresses rather than mitigates.
Cryptographically based bidirectional crosslink authentication prevents crafted traffic from a compromised neighbor from being accepted as legitimate.
Cryptographic bidirectional authentication on every commanding session — primary or backup — prevents IA-0004 from exploiting weaker authentication on the alternate path.
Authentication mandates apply to every command path including secondary receivers, defeating differences in vendor defaults that IA-0004.02 exploits.
Cryptographic bidirectional authentication on every command session forces commands from a compromised operator account to still pass per-session crypto, plus four-eyes-equivalent checks.
Authentication of every command session — only authenticated stations can establish a commanding link — directly defeats rogue external-entity transmissions.
Bidirectional cryptographic authentication on commands defeats traffic from an adversary-fielded ground station that lacks mission keys, regardless of RF/protocol fidelity.
Bidirectional cryptographic authentication on crosslinks rejects routing/time-distribution messages from an unauthenticated rogue spacecraft.
Authentication requirements apply uniformly across nominal and safe-mode states; cryptographic auth on every command denies the safe-mode-broader-acceptance pattern.
Cryptographic bidirectional crosslink authentication rejects routing/time-distribution and tasking messages from an unauthenticated compromised neighbor.
Cryptographically based bidirectional authentication on every commanding session prevents an unaffiliated ground station from establishing a commanding link.
Cryptographically based bidirectional authentication on every command session is the control that turns harvested command details into useless intelligence.
Cryptographic bidirectional authentication on TT&C sessions limits the value of captured uplink framing for an adversary attempting to impersonate the ground.