Annex 6.7.1
Mapped SPARTA techniques (30)
Techniques referencing this article
Network-security obligations cover the ground-side telemetry pipeline (reception, processing, display); the protections that resist downlink disruption ride on those network-security measures.
Inhibiting ground-system functionality acts on the entity's ground-segment networks and processing chain; network-security obligations cover the protections (boundary control, gateway monitoring, integrity verification of telemetry processing) that resist this attack.
Ground-based SDA pipelines are part of the entity's network-and-information-systems estate (or those of its SDA partners); network-security obligations cover the protection of observational feeds, catalog services and tracking-center networks.
Internal command/data buses (1553, SpaceWire, custom) are part of the network-and-information-systems estate; network-security measures apply to the protection of bus traffic from arbitrary injection or replay.
Network-security measures must remain in force across mode transitions; safe-mode does not exempt the entity from network-protection obligations, which is the implementing-regulation lever that closes the reduced-protection window the technique exploits.
Network-security obligations cover protection of links and processing paths from saturation; rate limiting, traffic shaping and ingress filtering at gateways are the network-security controls that absorb or shed flooding traffic.
Network-security obligations cover ingress hardening of receivers and parsers against malformed and noise inputs; this is the protective layer that prevents erroneous-input flooding from becoming a denial event.
Internal command/data buses are part of the entity's network estate; network-security obligations cover the protection of bus traffic from forged-frame injection through authentication, source restriction and segmentation.
Network-security obligations cover the protection of sensor-data interfaces between sensors and FSW; integrity protection on those interfaces resists fabricated-measurement injection.
Network-security obligations cover protection of traffic flows including measures that resist traffic analysis (cover traffic, padding, link-load smoothing) where appropriate to the risk profile.
Network-security obligations cover the protection of mission traffic in transit on ground LANs/WANs and across the space link; encryption, link-protection and integrity controls are the network-security measures that resist signal interception.
Network-security obligations cover the protection of uplink command traffic; link-encryption and integrity protection are the network-security measures that resist uplink-side interception of telecommand frames and file uploads.
Network-security obligations cover protection of downlink traffic on space-link and ground-side networks; link-layer encryption, integrity verification and signal-protection measures are the network-security measures that resist offline reconstruction of recorded downlinks.
Out-of-band communications links (rekeying channels, emergency commanding, beacons, custodial crosslinks) are part of the entity's network-and-information-systems estate; network-security obligations apply equally to secondary purpose-built channels and require the same protection as the primary TT&C.
Network-security obligations cover protection of crosslink and inter-vehicle traffic that a proximate adversary can observe; link-encryption and source authentication on those flows resist exfiltration value.
Network-security obligations cover the entire ground-segment estate where compromised-ground-system exfiltration occurs (operator workstations, mission-control servers, baseband chains, archive databases); boundary protection, gateway monitoring and traffic-egress controls are the network-security measures that bound mass exfiltration.
Cross-organization links (partner-station to MOC, processing partner to operator) are part of the entity's network-and-information-systems estate; network-security obligations apply to those gateways and resist man-in-the-middle exfiltration.
Inter-satellite link traffic between vehicles is part of the entity's network-and-information-systems estate; network-security obligations apply to the protection of crosslink data flows, route filtering and authentication of remote peers.
Backup TT&C and contingency MOC paths are part of the entity's network-and-information-systems estate; network-security obligations apply equally to the primary and the alternate, including cross-strapped paths.
The ground segment is the entity's primary network-and-information-systems estate; network-security measures (boundary protection, gateway hardening, monitoring of mission-control traffic) are the obligations under which the entity blocks ground-system compromise paths.
Network-security measures cover the air interface as part of the entity's network-and-information-systems estate; protection of the link from injection is a network-security obligation.
Network-security obligations apply to RF-link protection, including the cryptographic and protocol measures that resist injection from arbitrary transmitters.
Network-security measures must remain in force across mode transitions; safe-mode is a network-security context where reduced visibility creates the exact opportunity this technique exploits.
Network-security obligations cover the protection of mission data in transit (encryption, integrity, egress monitoring), reducing the value of intercepted or exfiltrated traffic offline.
Network-security obligations cover crosslink traffic between satellites; protection of routing updates, service advertisements and inter-vehicle data flows is part of the entity's network-security envelope.
Network-security measures protect operator workstations, mission-control servers and gateway equipment from persistent attacker presence; the network-security obligations are the protective envelope around the ground-segment infrastructure this technique inhabits.
Network-security obligations are the protection envelope around the entity's infrastructure; an adversary compromising existing infrastructure for staging is acting against precisely the controls Annex 6.7 requires the entity to maintain.
Network security obligations apply to the comms architecture and the protection of comms-configuration management — recon for the RF posture is fundamentally a network-security observable.
Network-security measures (link encryption, perimeter monitoring at ground stations, signal-protection treatment in mission planning) are the obligations under which the entity reduces uplink-intercept utility.
Network-security obligations cover the downlink processing chain at the entity's ground stations and require protection of telemetry pipelines from unauthorized observation.