Publication: enisa-stl-2025-03 Space Threat Landscape
Full text
The control text is third-party content; see the official source for the full wording.
Mapped SPARTA techniques
17 techniques
On-board IDS/IPS surfaces rootkit activity (hooked command handlers, falsified events) that masks malicious actions.
Establishing and documenting normal network activity for ground SDA mission applications is relevant to later anomaly detection, but the excerpt describes baselining rather than active detection or prevention of the ingestion saturation and track injection DE-0009.05 performs.
On-board IDS/IPS with response/log capability and integration with fault management surfaces malicious-code execution and supports countermeasure selection.
On-board IDS/IPS monitoring mission-critical components surfaces rootkit telemetry-filtering and command-handler-hooking activity even when system reports look healthy.
Intrusion detection and prevention with response capability detects flooding patterns and selects safe countermeasures (rate limiting, isolation).
On-board IDS/IPS surfaces excessive cadence of valid commands and selects safe countermeasures.
IDS/IPS detects malformed-traffic patterns and provides countermeasures within fault-management constraints.
Intrusion detection and prevention with documented baselines surfaces bulk extraction patterns and abnormal staging activity in ground systems.
Intrusion detection and prevention covering backup ground systems surfaces the establishment of presence on standby chains before they activate.
Intrusion detection and prevention with documented network baselines surfaces the deep reconnaissance and command preparation that defines IA-0007.
Intrusion detection and prevention on connections from partner enclaves identifies anomalies even when traffic originates from a trusted route.
Intrusion detection at the user-segment-to-mission boundary identifies malformed tasking requests propagating into payload scheduling.
Intrusion detection and prevention with documented baseline activities surfaces the late firmware loads, key/counter initialisation, and full-system rehearsals IA-0012 abuses.
Intrusion detection and prevention with documented baselines surfaces the durable reconnaissance and continuous staging that defines PER-0003 ground presence.
Intrusion detection and prevention on mission-critical components surfaces the compromise activity central to RD-0002.
Intrusion detection and prevention with traffic baselines for mission-operated ground systems detects the compromise activity that defines this sub-technique.
Intrusion detection and prevention on mission-critical components detects payload-delivery attempts at the boundary or on the spacecraft itself.