Annex 6.5.2
Mapped SPARTA techniques (9)
Techniques referencing this article
Onboard SSA/SDA sensor-deception testing scope (proximity-sensor fusion under hostile inputs, dazzling/spoofing scenarios) is what Annex 6.5.2 requires the entity to define for the proximity-awareness portion of its security-testing program.
Component-collusion testing scope (cross-module behavioural analysis, integration-level security testing) is what Annex 6.5.2 requires the entity to define under risk-assessment-driven testing.
Primary mapping to Annex 6.5.1 (security-testing policy) for code-flaw exploitation implies Annex 6.5.2 obligations: the entity must establish need, scope and types of testing based on risk assessment, including the parser/library/driver classes a code-flaw adversary targets.
Flight-software command/telemetry handlers, table loaders and file-transfer services are exactly the test-scope items Annex 6.5.2 requires the entity to define under risk assessment, including fuzzing of parsers and integration testing on flatsats.
Erroneous-input-flooding test scope (telecommand-parser fuzzing, malformed-frame ingestion testing) is exactly the procedural detail Annex 6.5.2 requires the entity to define under its testing policy.
Sensor-data-spoofing testing scope (sensor-fusion sanity checks, outlier-rejection logic, estimator robustness under fabricated measurements) is what Annex 6.5.2 requires the entity to define for its security-testing policy.
Backdoor-detection testing scope (static analysis, taint analysis, integration-level authentication tests) is what Annex 6.5.2 requires the entity to define for its security-testing policy.
Software-backdoor testing scope (taint analysis, behavioral testing of authentication paths, hidden-handler discovery) is what Annex 6.5.2 requires the entity to define under risk-assessment-driven testing.
Security-testing-tools reconnaissance targets the same testing scope Annex 6.5.2 requires the entity to define; the policy that codifies what is tested also codifies what knowledge of testing must remain confidential.