Transmitted Data Manipulation
Parent: T1565
Description
Adversaries may alter data en route to storage or other systems in order to manipulate external outcomes or hide activity, thus threatening the integrity of the data.(Citation: FireEye APT38 Oct 2018)(Citation: DOJ Lazarus Sony 2018) By manipulating transmitted data, adversaries may attempt to affect a business process, organizational understanding, and decision making. Manipulation may be possible over a network connection or between system processes where there is an opportunity deploy a tool that will intercept and change information. The type of modification and the impact it will have depends on the target transmission mechanism as well as the goals and objectives of the adversary. For complex systems, an adversary would likely need special expertise and possibly access to specialized software related to the system that would typically be gained through a prolonged information gathering campaign in order to have the desired impact.
Mapped SPARTA techniques
7 techniques
Sensor deception is achieved by injecting falsified signals into the sensor's input chain — T1565.002 'Transmitted Data Manipulation' covers the underlying mechanism (manipulation of data en route to the sensor). Cross-tactic moderate (impact vs defense-evasion).
PNT geofencing is induced by manipulating the navigation signals in transit (GNSS spoofing) so the spacecraft's onboard logic triggers geofence-conditioned behavior; T1565.002 'Transmitted Data Manipulation' is the conceptual match (manipulating data in transit to influence target behavior). Cross-tactic moderate because T1565.002 sits in impact (post-access) while SPARTA EX-0002 is execution (during exploitation).
T1565.002 'Transmitted Data Manipulation' addresses adversary alteration of data in transit to influence outcomes; SPARTA EX-0014 'Spoofing' is the parent-level equivalent for spoofing signals/data sent to the spacecraft. Cross-tactic moderate (impact vs execution).
Time-spoofing (sending falsified time messages or PPS pulses) is manipulation of transmitted time-reference data; T1565.002 'Transmitted Data Manipulation' covers this at cross-tactic level.
Bus traffic spoofing (forging packets on internal buses like 1553/SpaceWire/CAN) is manipulation of transmitted data on the bus medium; T1565.002 'Transmitted Data Manipulation' covers this at cross-tactic level.
Spoofing sensor data (injecting falsified readings on sensor lines or in transit between sensor and OBC) is transmitted-data manipulation at the sensor-bus level; T1565.002 covers this exact concept.
PNT spoofing (injecting falsified GNSS signals into the spacecraft's navigation receiver) is the canonical example of transmitted-data manipulation in the space domain; T1565.002 covers this exact pattern with cross-tactic moderate confidence.
Cross-framework references
Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.
Countered by 9 in MITRE D3FEND (Defensive Techniques)
- D3-APCAApplication Protocol Command Analysis
- D3-CSPPClient-server Payload Profiling
- D3-NTCDNetwork Traffic Community Deviation
- D3-NTFNetwork Traffic Filtering
- D3-NTSANetwork Traffic Signature Analysis
- D3-PHDURAPer Host Download-Upload Ratio Analysis
- D3-PMADProtocol Metadata Anomaly Detection
- D3-RTSDRemote Terminal Session Detection
- D3-UGLPAUser Geolocation Logon Pattern Analysis
Cite as SafeMode Space, mitre-attack-enterprise T1565.002.