All techniques
DE-0010
ST0006Defense Evasion

Overflow Audit Log

Description

The adversary hides activity by exhausting finite on-board logging and telemetry buffers so incriminating events are overwritten before they can be downlinked. Spacecraft typically use ring buffers with severity filters, per-subsystem quotas, and scheduled dump windows; by generating bursts of benign but high-frequency events (file listings, status queries, low-severity housekeeping, repeated mode toggles) or by provoking chatter from chatty subsystems, the attacker accelerates rollover. Variants target recorder indexes and event catalogs so new entries displace older ones, or they align floods with known downlink gaps and pass handovers when retention is shortest. To analysts on the ground, logs appear present but incomplete, showing a plausible narrative that omits the very interval when unauthorized commands or updates occurred.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(h)
    addresses
    moderate
    inferred

    CRA Annex I (2)(h) availability is domain-relevant but does not mitigate DE-0010: log/telemetry buffer exhaustion hides activity via rollover while essential functions stay available. The operative controls are protected non-wrapping audit storage and logging-integrity monitoring. Addresses.

  • craAnnex I, Part I, (2)(l)
    addresses
    high
    direct

    Exhausting ring buffers and recorder indexes so incriminating events overflow before downlink directly defeats (2)(l)'s record-and-monitor obligation; product design must provide reliable retention of security-relevant events.

  • eu-space-actArt. 83(1)
    addresses
    high
    direct

    Audit-log overflow defeats 83(1)'s monitoring obligation by overwriting incriminating events; reliable retention of security-relevant events is part of the monitoring discipline.

  • eu-space-actArt. 84(2)
    addresses
    moderate
    inferred

    Art. 84(2)'s comply-with-Annex-VII-5.1 reference is domain-relevant to log-overflow, but names no specific interdicting mechanism in the cited text.

  • nis2Art. 21(2)(b)
    addresses
    high
    derived

    Buffer rollover bursts of benign-but-high-frequency events aligned with downlink gaps are detectable log-integrity signals; Art. 21(2)(b)'s incident-handling capability must include log-volume baselines and ground-side ring-buffer cross-checks.

  • nis2Art. 21(2)(i)
    addresses
    moderate
    direct

    Log buffer parameters (severity filters, per-subsystem quotas, dump-window scheduling) and recorder/event catalogs are access-controlled engineering configuration; Art. 21(2)(i)'s access-control + asset-management obligation governs edits that change retention behaviour.

  • nis2-implAnnex 3.2.3
    addresses
    high
    derived

    Maintaining and documenting logs is the operational discipline that supports periodic offload of log content before overflow can occur; the obligation requires logs to be maintained, not lost to ring-buffer wraparound.

  • nis2-implAnnex 3.2.5
    addresses
    high
    direct

    The implementing regulation requires logs to be maintained for a predefined period and protected from unauthorised access; deliberately overflowing finite log buffers to overwrite incriminating events directly contradicts that obligation, and the protective measures it requires bound the success of log overflow.

  • nis2-implAnnex 3.2.7
    addresses
    moderate
    derived

    Periodic review of the logging procedures and asset list ensures that buffer sizing, severity quotas and per-subsystem logging configuration are calibrated to prevent unintended log overflow.

ENISA controls

  • Anomaly detection with established baselines for network operations and event correlation flags abnormal log-generation rates.

  • Capacity sizing for cyber-relevant peak load (including event/log generation) prevents on-board log buffers from rolling over before downlink.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, DE-0010 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.