Runtime Data Manipulation
Parent: T2054
Description
An attacker can use a controlled payload software or component to manipulate data of that or another component during the execution, if a MMU or a MPU is not implemented or is misconfigured. Only the most recent space qualified microprocessors (LEONII/III) have a MMU available, that provides only write protection. For secure spacecraft avionics, protection against read/write and execution access is necessary. The MMU or a MPU is extremely important if the payload is not trusted. (Citation: MITRE ATT&CK) (Citation: SRC015)
Mapped SPARTA techniques
6 techniques
T2054.003 'Runtime Data Manipulation' covers manipulating data during execution — addresses DE-0003.09's biasing of the spacecraft's authoritative time source via clock-register writes and disciplining-source switches at runtime.
T2054.003 'Runtime Data Manipulation' covers manipulating data of components during execution — addresses EX-0012.01's modification of internal registers as the FSW is functioning.
T2054.003 'Runtime Data Manipulation' covers manipulating data during execution — addresses EX-0012.12's writing to clock registers and switching disciplining sources at runtime.
T2054.003 'Runtime Data Manipulation' covers altering data during execution — addresses EX-0014.01's biasing of distributed time service values that downstream consumers use for sequencing, anti-replay, and navigation filtering.
T2054.003 'Runtime Data Manipulation' covers manipulating data during execution — addresses EX-0014.02's forging of frames with valid identifiers on internal command/data paths so subscribers accept attacker-controlled values at runtime.
T2054.003 covers runtime data manipulation — addresses EX-0014.03's injection of fabricated sensor measurements at sensor-gateway interfaces that estimation/control treat as ground truth at runtime.
Cite as SafeMode Space, space-shield T2054.003.