All techniques
DE-0009.05
ST0006Defense Evasion
sub-technique

Corruption or Overload of Ground-Based SDA Systems

Parent: DE-0009

Description

The adversary targets terrestrial space-domain awareness pipelines, sensor networks, tracking centers, catalogs, and their data flows, to blind or confuse broad-area monitoring. Paths include compromising or spoofing observational feeds (radar/optical returns, TLE updates, ephemeris exchanges), injecting falsified or time-shifted tracks, tampering with fusion/association parameters, and saturating ingestion and alerting with noisy or adversarial inputs. Where SDA employs AI/ML for detection and correlation, the attacker can degrade models by flooding them with ambiguous scenes or crafted features that increase false positives/negatives and consume analyst cycles. Unlike onboard deception, this approach skews the external decision-support picture across many assets at once, delaying detection of real maneuvers and providing cover for concurrent operations.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(f)
    addresses
    high
    direct

    Compromising or spoofing observational feeds, injecting falsified tracks, and tampering with fusion/association parameters are unauthorized modifications of the SDA product's processed data — within (2)(f)'s integrity scope.

  • craAnnex I, Part I, (2)(h)
    addresses
    high
    direct

    Saturating ingestion and alerting with noisy or adversarial inputs is a denial-of-service / overload condition (2)(h) requires resilience and DoS-mitigation measures against.

  • craAnnex I, Part I, (2)(k)
    addresses
    moderate
    inferred

    CRA Annex I (2)(k) is domain-relevant but does not mitigate DE-0009.05: terrestrial SDA spoofing skews external decision-support (deception), not the product's availability. The operative controls are SDA data-source authentication and corroboration. Addresses.

  • craAnnex I, Part II, (3)
    addresses
    moderate
    direct

    Ground-SDA corruption/overload (primary mapping: Annex I, Part I, (2)(k)) requires regular tests under (3) of the ingestion and detection-model robustness against adversarial inputs.

  • eu-space-actArt. 83(1)
    addresses
    moderate
    direct

    Saturation of SDA ingestion and alerting attacks the monitoring discipline 83(1) places on ground systems — operator-side input validation and rate limiting reduce adversarial-input impact.

  • eu-space-actArt. 84(2)
    addresses
    moderate
    direct

    Compromise/spoofing of ground-SDA observational feeds and falsified-track injection corrupts network-and-information-system data — 84(2)'s Annex VII point 5.1 integrity scope applies to ground SDA pipelines.

  • eu-space-actArt. 84(4)
    addresses
    moderate
    direct

    84(4)'s preventive and protective measures regarding the ground segment (Annex VII point 5.4) cover the operator's design discipline against ground-SDA pipeline corruption.

  • nis2Art. 21(2)(b)
    addresses
    high
    derived

    Saturated ingestion, falsified TLE updates, and adversarial-input floods on terrestrial SDA pipelines are detectable as integrity incidents Art. 21(2)(b)'s incident-handling capability must surface across the SDA monitoring surface.

  • nis2Art. 21(2)(d)
    addresses
    moderate
    direct

    SDA partner data flows (radar/optical sensor networks, ephemeris exchanges, fusion partners) ride supplier and service-provider relationships; Art. 21(2)(d)'s supplier-relationship security obligation governs the trust framework around those sources.

  • nis2Art. 21(2)(e)
    addresses
    moderate
    direct

    SDA software/ML-pipeline integrity (fusion/association code, detection models, ingest validators) is part of Art. 21(2)(e)'s network-and-information-systems development/maintenance + vulnerability-handling obligation, including disclosed weaknesses in those services.

  • nis2Art. 21(3)
    addresses
    moderate
    derived

    Primary mapping to Art. 21(2)(d) governs supplier security for SDA/SSA telemetry feeds. Art. 21(3) procedurally extends that to vulnerability assessment and secure-development scrutiny of the SDA vendor, which is where the corruption-or-overload pre-conditions are introduced.

  • nis2-implAnnex 3.2.1
    addresses
    moderate
    derived

    Monitoring-and-logging procedures should surface SDA-feed anomalies, catalog-update inconsistencies and sensor-correlation drop-outs that signal SDA-pipeline compromise or spoofing.

  • nis2-implAnnex 5.1.1
    addresses
    moderate
    derived

    External SDA providers (commercial and government) are direct suppliers under the supply-chain policy; the policy governs how the entity vets, contracts with and monitors the data flows from those tracking centers.

  • nis2-implAnnex 6.7.1
    addresses
    moderate
    derived

    Ground-based SDA pipelines are part of the entity's network-and-information-systems estate (or those of its SDA partners); network-security obligations cover the protection of observational feeds, catalog services and tracking-center networks.

ENISA controls

  • Third-party risk management covers SDA partners whose compromised feeds DE-0009.05 spoofs or saturates.

  • Establishing and documenting normal network activity for ground SDA mission applications is relevant to later anomaly detection, but the excerpt describes baselining rather than active detection or prevention of the ingestion saturation and track injection DE-0009.05 performs.

  • ML data-integrity testing surfaces poisoning of SDA AI/ML detection and correlation models through regression, validity, and statistical analysis.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, DE-0009.05 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.