All techniques
DE-0009.04
ST0006Defense Evasion
sub-technique

Targeted Deception of Onboard SSA/SDA Sensors

Parent: DE-0009

Description

The attacker aims at the spacecraft’s own proximity-awareness stack, cameras, star-tracker side products, lidar/radar, RF transponders, and the onboard fusion that estimates nearby objects. Methods include optical dazzling or reflective camouflage that confuses centroiding and detection, RCS management to fall below radar gate thresholds, intermittent or misleading transponder replies, and presentation of spoofed fiducials or optical patterns tuned to the vehicle’s detection algorithms. By biasing these local sensors and their fusion logic, the adversary hides approach, distorts relative-state estimates, or induces the target to classify a nearby object as benign clutter, masking proximity operations without relying on external catalog errors.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(d)
    addresses
    moderate
    direct

    Intermittent or misleading transponder replies and spoofed RF identities are authentication failures of the proximity-identification protocol — within (2)(d)'s authentication and report-on-unauthorised-access scope.

  • craAnnex I, Part I, (2)(k)
    addresses
    moderate
    inferred

    CRA Annex I (2)(k) is domain-relevant but does not mitigate DE-0009.04: onboard proximity-sensor deception distorts relative-state estimates (a deception vector), not an incident-impact availability loss. The operative controls are sensor-fusion integrity and cross-checks. Addresses.

  • craAnnex I, Part II, (3)
    addresses
    moderate
    direct

    Onboard SSA/SDA-sensor deception (primary mapping: Annex I, Part I, (2)(k)) requires regular tests under (3) of the fusion algorithm's robustness against adversarial inputs (dazzling, spoofed transponder replies).

  • eu-space-actArt. 76(2)
    addresses
    moderate
    inferred

    Art. 76(2)(a)'s ensure-resilience obligation is domain-relevant to onboard SSA/SDA-sensor deception, but the generic resilience mandate names no mechanism interdicting the deception vector; sensor-fusion validation and input authentication would be the interdicting controls.

  • eu-space-actArt. 84(2)
    addresses
    moderate
    inferred

    Art. 84(2)'s comply-with-Annex-VII-5.1 reference is domain-relevant to sensor deception but names no specific interdicting mechanism; sensor-fusion validation would be the interdiction.

  • nis2Art. 21(2)(b)
    addresses
    moderate
    derived

    On-board SSA/SDA fusion anomalies (centroiding inconsistencies, transponder-reply gaps, RCS misclassifications) are detectable via multi-source cross-correlation; Art. 21(2)(b)'s incident-handling capability must surface those proximity-awareness signals.

  • nis2-implAnnex 13.2.1
    addresses
    moderate
    derived

    Optical dazzling, reflective camouflage and corner-cube spoofing target the spacecraft's onboard sensors physically; the protection-against-physical-and-environmental-threats obligation covers aperture-cover design, filter selection and other mitigations against directed-optical effects.

  • nis2-implAnnex 6.5.1
    addresses
    moderate
    derived

    Security-testing policies should exercise sensor-fusion sanity checks and outlier-rejection logic; the proximity-sensor deception this technique describes exploits gaps in those onboard fusion mechanisms.

  • nis2-implAnnex 6.5.2
    addresses
    moderate
    derived

    Onboard SSA/SDA sensor-deception testing scope (proximity-sensor fusion under hostile inputs, dazzling/spoofing scenarios) is what Annex 6.5.2 requires the entity to define for the proximity-awareness portion of its security-testing program.

  • nis2-implAnnex 6.5.3
    addresses
    moderate
    derived

    Annex 6.5.3 review-cadence applies to proximity-sensor testing scope to keep pace with adversary-deception capability evolution.

ENISA controls

  • Criticality analysis identifying the proximity-awareness fusion stack as mission-critical prioritises protection and is relevant, but criticality analysis is a governance control and does not itself actively defend against the sensor deception DE-0009.04 performs.

  • Real-time physics-model verification of inputs to satellite bus and payload flags fabricated SSA/SDA returns that violate physical plausibility of nearby objects.

  • Reinforcement-learning anomaly detection that ignores malicious data is positioned to filter spoofed fiducials and dazzling-induced sensor outputs.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, DE-0009.04 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.