All techniques
DE-0004
ST0006Defense Evasion

Masquerading

Description

The adversary presents themselves as an authorized origin so activity appears legitimate across RF, protocol, and organizational boundaries. Techniques include crafting telecommand frames with correct headers, counters, and dictionaries; imitating station “fingerprints” such as Doppler, polarization, timing, and framing; replaying or emulating crosslink identities; and using insider-derived credentials or roles to operate mission tooling. Masquerading can also target metadata, virtual channel IDs, APIDs, source sequence counts, and facility identifiers, so logs and telemetry attribute actions to expected entities. The effect is that commands, file transfers, or configuration changes are processed as if they came from approved sources, reducing scrutiny and delaying detection.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(d)
    addresses
    high
    direct

    Masquerading by crafting authenticated-looking telecommand frames, imitating station fingerprints, or replaying crosslink identities is the canonical authentication-bypass attack (2)(d) requires the product's access-management mechanisms to resist.

  • craAnnex I, Part I, (2)(f)
    addresses
    moderate
    direct

    Tampering with virtual channel IDs, APIDs, and source sequence counts to misattribute logs is unauthorized modification of stored/transmitted data within (2)(f)'s scope.

  • eu-space-actArt. 84(3)
    mitigates
    moderate
    direct

    84(3)'s only-authorized-devices rule applies to crosslink and bus participants — preventing masqueraded peer identities from being honored.

  • eu-space-actArt. 85(1)
    addresses
    high
    direct

    Masquerading defeats authentication — 85(1)'s cryptographic concept defines the authentication mechanisms (telecommand MACs, station-fingerprint resistance, crosslink auth) that defeat impersonation.

  • eu-space-actArt. 85(2)
    addresses
    moderate
    direct

    Masquerading (primary: Art. 85(1)/(3)) cascades to 85(2) — key lifecycle policy ensures masquerading-relevant keys (signing/MAC) follow secure generation/storage/rotation.

  • eu-space-actArt. 85(3)
    addresses
    high
    direct

    85(3)(a)'s end-to-end authentication between satellite control centres and space segment is the cryptographic discipline that prevents masqueraded telecommands from being accepted regardless of RF correctness.

  • nis2Art. 21(2)(b)
    addresses
    moderate
    derived

    Origin-attribution mismatches (VCID/APID/source-sequence-count anomalies, unexpected facility identifiers, station-fingerprint deviations) are detectable; Art. 21(2)(b)'s incident-handling capability must surface those signals from cross-source authentication telemetry.

  • nis2Art. 21(2)(h)
    addresses
    moderate
    direct

    Art. 21(2)(h) requires the entity to maintain cryptography policies and procedures covering link-layer and crosslink authentication; that governance obligation addresses masquerading by mandating the authentication measures, while the deployed authentication and identity binding, not the policy article, are what reject crafted frames presented as an authorised origin.

  • nis2Art. 21(2)(j)
    addresses
    moderate
    direct

    MFA/continuous authentication on operator tools and mission consoles under Art. 21(2)(j) defeats insider-credential masquerading at the ground-side end of the chain.

  • nis2-implAnnex 11.5.1
    addresses
    moderate
    derived

    Identity life-cycle management ensures the population of legitimate identities is constrained and current, narrowing the surface for masquerading as an authorized actor.

  • nis2-implAnnex 11.6.1
    addresses
    high
    derived

    Secure-authentication procedures bind activity to verifiable identities; properly implemented authentication denies an adversary the ability to credibly present as an authorized origin without valid keys or factors.

ENISA controls

  • Communications security with imitative/manipulative deception detection identifies and rejects masqueraded transmissions based on signal parameters.

  • Cryptography and key management denies the keys needed to forge cryptographically-authenticated traffic, but DE-0004 masquerades across multiple layers: RF-fingerprint imitation (Doppler, polarization, timing, and framing), insider-derived credentials that already pass authentication, and metadata or identifier spoofing for false attribution. Crypto interdicts one vector, not the dominant multi-layer masquerade scope, so the relationship is addresses.

  • Cryptographic bidirectional authentication on every command session denies masqueraded origins acceptance, regardless of how authentic the framing appears.

  • Insider Threat Protection governs policies and procedures to prevent insiders from masquerading as valid commanding personnel, relevant to one facet of DE-0004 at the governance level rather than actively defending the RF/protocol masquerading.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, DE-0004 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.