All techniques
DE-0003.09
ST0006Defense Evasion
sub-technique

System Clock for Evasion

Parent: DE-0003

Description

The adversary biases the spacecraft’s authoritative time so that telemetry, event logs, and command histories appear shifted or inconsistent. By writing clock registers, altering disciplining sources (e.g., GNSS vs. free-running oscillator), or tweaking distribution services and offsets, they can make stored commands execute “earlier” or “later” on the timeline and misalign acknowledgments with actual actions. Downlinked frames still carry plausible timestamps near packet headers, but those stamps no longer reflect when data was produced, complicating reconstruction of sequences and masking causality during incident analysis.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(f)
    addresses
    high
    direct

    Biasing the spacecraft's authoritative time — writing clock registers, altering disciplining sources — is unauthorized modification of stored configuration that propagates into telemetry timestamps and command histories, within (2)(f)'s integrity scope.

  • craAnnex I, Part I, (2)(l)
    addresses
    moderate
    direct

    Reliable timestamps are foundational to (2)(l)'s recording-and-monitoring obligation; clock-bias evasion defeats reconstruction of sequences and causality during incident analysis.

  • eu-space-actArt. 84(2)
    addresses
    moderate
    direct

    System-clock biasing attacks the network-and-information-system time integrity per 84(2)'s Annex VII point 5.1 requirements.

  • eu-space-actArt. 85(2)
    addresses
    moderate
    inferred

    Art. 85(2)'s key-lifecycle policy is crypto-domain-relevant to DE-0003.09, but key lifecycle does not interdict clock-source biasing; authenticated time distribution would be the interdicting mechanism.

  • nis2Art. 21(2)(b)
    addresses
    moderate
    derived

    Time-base discontinuities (clock-register writes, disciplining-source switches, distribution-service offsets) are detectable via multi-source corroboration; Art. 21(2)(b)'s incident-handling capability must surface those anomalies for forensic reconstruction.

  • nis2Art. 21(2)(h)
    addresses
    moderate
    direct

    Authenticated time service and integrity-protected disciplining sources under cryptography policy at Art. 21(2)(h) defeat the time-bias attack the technique uses to misalign acknowledgments and stored sequence execution.

  • nis2-implAnnex 3.2.6
    addresses
    high
    derived

    The synchronized-time-source obligation requires reliable time bases for log correlation and event ordering; clock biasing for evasion is precisely what that obligation is established to detect via cross-source disagreement.

  • nis2-implAnnex 6.4.1
    addresses
    moderate
    derived

    Clock writes and time-discipline source changes are change-management events with significant downstream effects; documented procedures must govern such modifications.

ENISA controls

  • Configuration management of clock disciplining sources and time-service settings detects unauthorised slewing for evasion.

  • Resilient PNT with fault-tolerant authoritative time sourcing across processors counters unauthorised system-clock biasing for evasion.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, DE-0003.09 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.