Modification of On Board Control Procedures modification
Description
An On-Board Control Procedure (OBCP) is a software program designed to be executed by an OBCP engine, which can be loaded, executed, and also replaced, on-board the spacecraft. An attacker can attempt to modify them to execute her own commands and control the spacecraft. The attacker can attempt to modify OBCP to gain access to the interface of the On-Board Computer (OBC) and interact with it. In New Space mission, and in general missions using CubeSats, Execution can include exploitation of Micropython flaws or vulnerabilities or using Shell commands for various purposes (further reconnaissance, privilege escalation, launching attacks like Denial of Service, take full control of spacecraft, etc.). Standard/references: (Citation: SRC023)
Mapped SPARTA techniques
4 techniques
T2010 'Modification of On Board Control Procedures' covers attackers modifying OBCPs to execute crafted commands; EX-0002 PNT Geofencing implements such conditional execution via OBCPs that monitor navigation/ephemeris state, so T2010 is the SPACE-SHIELD substrate. No direct PNT-trigger technique exists in SPACE-SHIELD.
T2010 'Modification of On Board Control Procedures' covers OBCP modification to execute attacker-controlled commands; EX-0008 Time Synchronized Execution is implemented via OBCPs scheduled against onboard clocks/counters, so T2010 is the SPACE-SHIELD substrate. No direct timing-trigger technique exists at the sub-technique level.
T2010 'Modification of On Board Control Procedures' covers attackers modifying OBCPs to execute their own commands — addresses the 'data payloads that an interpreter treats as code' subset of EX-0010 (procedure languages, table-driven automations).
T2010 'Modification of On Board Control Procedures' covers loading and replacing OBCPs onboard — addresses EX-0012.03's seeding of scripts/procedures into interpreter buffers via load services.
Cite as SafeMode Space, space-shield T2010.