All techniques
DE-0003.10
ST0006Defense Evasion
sub-technique

GPS Ephemeris

Parent: DE-0003

Description

A satellite with a GPS receiver can use ephemeris data from GPS satellites to estimate its own position in space. A hostile actor could spoof the GPS signals to cause erroneous calculations of the satellite’s position. The received ephemeris data is often telemetered and can be monitored for indications of GPS spoofing. Reception of ephemeris data that changes suddenly without a reasonable explanation (such as a known GPS satellite handoff), could provide an indication of GPS spoofing and warrant further analysis. Threat actors could also change the course of the vehicle and falsify the telemetered data to temporarily convince ground operators the vehicle is still on a proper course.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(f)
    addresses
    high
    direct

    Falsifying telemetered ephemeris data to deceive ground operators is unauthorized modification of transmitted data — the integrity property (2)(f) addresses with its corruption-reporting requirement.

  • eu-space-actArt. 76(2)
    addresses
    moderate
    inferred

    Art. 76(2)(a)'s ensure-resilience obligation is domain-relevant to ephemeris manipulation, but the generic mandate names no interdicting mechanism; PNT cross-checks and integrity monitoring would interdict.

  • eu-space-actArt. 84(2)
    addresses
    moderate
    direct

    Spoofed GPS ephemeris feeding into telemetered position estimates corrupts network-and-information-system data — within 84(2)'s integrity scope.

  • nis2Art. 21(2)(b)
    addresses
    moderate
    derived

    Sudden ephemeris jumps without known GPS-handoff context are detectable cross-source anomalies; Art. 21(2)(b)'s incident-handling capability must surface those signals to flag GPS-spoofing-driven evasion.

  • nis2-implAnnex 13.2.1
    addresses
    moderate
    derived

    GPS-ephemeris spoofing of the on-board receiver is an RF-environmental threat; protection-against-physical-and-environmental-threats obligations cover anti-spoofing receiver design, multi-source cross-checks and integrity-monitoring fall-back.

  • nis2-implAnnex 3.2.1
    addresses
    moderate
    derived

    Monitoring procedures must surface PNT-solution anomalies (impossible jumps, cross-source disagreements with onboard ephemeris) that signal GPS-ephemeris spoofing.

ENISA controls

  • Resilient PNT with GNSS authentication and trusted-source verification defeats GPS-ephemeris biasing of the on-board position estimate.

  • Critical-telemetry-points monitoring on the telemetered ephemeris flags sudden changes consistent with spoofing — explicitly suggested in the SPARTA description.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, DE-0003.10 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.