Annex I, Part I, (2)(j)
Mapped SPARTA techniques (29)
Techniques referencing this article
Limited attack surfaces apply to internal bus interfaces; manufacturers must constrain which transmit nodes can produce traffic for which subscribers.
Limited attack surfaces include hardware test/maintenance modes; manufacturers must design products to disable, lock or destroy these surfaces post-deployment.
Limited attack surfaces obligation requires manufacturers to remove or disable maintenance shells, management consoles and unused kernel primitives in production firmware — exactly the OS-level surface this technique targets.
Limited attack surfaces apply to register-level/maintenance interfaces; manufacturers must lock or destroy them post-deployment.
Limited attack surfaces define which trust domains can publish to which subscribers; manufacturers must enforce these boundaries in routing-table policy.
Limited attack surfaces include raw memory-write interfaces; manufacturers must disable or constrain such interfaces post-deployment.
Limited attack surfaces include bus-segment trust domains; manufacturers must enforce origin restrictions on bus-message production.
Secondary purpose-built links (rekeying, emergency commanding, beacons, custodial crosslinks) ARE external interfaces in the (2)(j) sense; the limit-attack-surfaces obligation requires these auxiliary surfaces to be hardened and not available as covert exfiltration paths.
Payload comms separate from primary TT&C is exactly the kind of additional external interface (2)(j) requires the product designer to constrain — particularly when bus data can be routed into channels that bypass TT&C monitoring.
Limited attack surfaces apply to crosslink-facing functions; minimising trust granted to neighboring vehicles bounds the bridgehead-from-neighbor risk.
Limited attack surfaces apply to secondary/backup interfaces; manufacturers should design backup channels to be activated only when needed and locked down by default.
Limited attack surfaces apply to backup receivers; cross-strapped or alternate front ends should be locked down except when actively required.
Limited attack surfaces apply to host-bus/payload gateway interfaces; manufacturers must design products to expose minimal trust through these gateways to prevent payload-to-bus pivot.
Limited attack surfaces apply to ground-system products; manufacturers must minimise external interfaces (admin consoles, debug ports, management APIs) on operator workstations and mission-control servers.
Limited attack surfaces on proximity-facing interfaces bound what a rogue-spacecraft peer can interact with even when within RF range.
Limited attack surfaces apply to user-segment-facing interfaces (terminal APIs, customer gateways); products should expose minimal trust through these edges to prevent user-segment compromise propagating into mission systems.
Limited attack surfaces apply to peripheral and removable-media interfaces; manufacturers must constrain what auxiliary devices can ingest into the product.
Limited attack surfaces during AIT-time integration constrain the ingress points adversaries exploit when EGSE, simulators and flatsats touch flight interfaces.
Limited attack surfaces apply to host-bus/payload interfaces from the host-bus side: manufacturer must design the host bus to expose minimal trust to the hosted payload.
The host–payload boundary IS an external interface and shared-bus interaction surface; (2)(j)'s limit-attack-surfaces obligation places product-design responsibility on segmenting it.
A flat shared bus with minimal partitioning is exactly the unbounded internal attack surface (2)(j)'s limit-attack-surfaces obligation requires the product designer to constrain through segmentation, role enforcement, and gateway controls.
Crosslink gateways into command/data paths are an external-interface attack surface; (2)(j)'s limit-attack-surfaces obligation constrains what the gateway accepts from peers.
Visiting-vehicle interfaces are external interfaces in the most literal (2)(j) sense; the limit-attack-surfaces obligation applies to docking handshakes and umbilical service channels.
Inter-partition communication channels (message ports, shared memory, virtual NICs, hypercalls) ARE the attack surface (2)(j)'s obligation requires the product to limit and harden.
Umbilicals, separation avionics, and shared EGSE networks are external interfaces (2)(j) requires the product to limit; tight integration timelines are not an exemption from the design obligation.
Shared data buses, deployer controllers, and common logging collectors used by rideshare neighbors are the precise multi-tenant attack surface (2)(j)'s limit-attack-surfaces obligation requires payload manufacturers to constrain via isolation.
(2)(j) attack-surface limitation reduces cross-domain gateway count but does not interdict honoring of reused valid credentials; access control and least-privilege scoping (2)(d) interdict the credential-reuse lateral path, so (2)(j) addresses surface exposure.
Limited attack surfaces on ground-system products bound the surface where persistent attacker presence can hide; manufacturers must minimise admin consoles, debug ports and management APIs.
Manufacturers must design products to limit attack surfaces, including external interfaces; products that minimise commanding-interface exposure (mode-bound commands, locked-down maintenance dictionaries) reduce the value of commanding-detail reconnaissance.