All techniques
EX-0001
ST0004Execution

Replay

Description

Replay is the re-transmission of previously captured traffic, over RF links, crosslinks, or internal buses, to elicit the same processing and effects a second time. Adversaries first observe and record authentic exchanges (telecommands, ranging/acquisition frames, housekeeping telemetry acknowledgments, bus messages), then resend them within acceptance conditions that the system recognizes, matching link geometry, timetags, counters, or mode states. The aim can be functional (re-triggering an action such as a mode change), observational (fingerprinting how the vehicle reacts at different states), or disruptive (saturating queues and bandwidth to crowd out legitimate traffic). Because replays preserve valid syntax and often valid context, they can blend with normal operations, especially during periods with reduced monitoring or when counters and windows reset (e.g., handovers, safing entries). On encrypted links, metadata replays (acquisition beacons, schedule requests) may still yield informative responses.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(d)
    mitigates
    moderate
    derived

    Manufacturer authentication obligations include replay-resistant mechanisms (counters, timestamps, MAC binding); products designed under (2)(d) reject re-sent traffic and convert replay attempts into immediate rejection.

  • craAnnex I, Part I, (2)(f)
    addresses
    moderate
    derived

    Integrity protection of stored, transmitted and processed commands and programs ensures duplicated frames do not pass integrity checks; replay defeats by integrity binding.

  • eu-space-actArt. 85(1)
    addresses
    high
    direct

    85(1)'s cryptographic concept must define anti-replay handling (counters, timetags, freshness windows) — the core protection against the EX-0001 family.

  • eu-space-actArt. 85(2)
    addresses
    high
    direct

    Replay (primary: Art. 85(1)/(3)) cascades to 85(2) — anti-replay counters and key rotation are part of the key lifecycle policy.

  • eu-space-actArt. 85(3)
    addresses
    high
    direct

    85(3)(b)'s telecommand-encryption obligation, paired with anti-replay counters that 85(3) presumes, is the cryptographic discipline that defeats RF and crosslink replay.

  • nis2Art. 21(2)(b)
    addresses
    moderate
    derived

    Repeated/duplicate frames, queue-saturating streams, and unexplained mode changes are observable replay artefacts the entity's incident-handling capability under Art. 21(2)(b) must surface from baseline command volumes.

  • nis2Art. 21(2)(h)
    addresses
    high
    direct

    Art. 21(2)(h) obliges the entity to hold cryptography policies and procedures covering anti-replay and message authentication; it addresses replay by requiring those measures, while the deployed anti-replay state and MAC-bound counters, not the policy article, are what make captured traffic ineffective on retransmission.

  • nis2-implAnnex 11.6.1
    addresses
    high
    inferred

    Authentication based on access control is domain relevant but does not interdict replay; anti-replay freshness (counters, timestamps, nonces) is the control that converts a captured-and-replayed message into a rejected one.

  • nis2-implAnnex 3.2.1
    addresses
    moderate
    derived

    Monitoring-and-logging procedures must surface duplicate or out-of-sequence command/data events; replay attempts are observable in command counters and audit trails.

ENISA controls

  • Communications security with detection of imitative deception flags and rejects replayed wireless transmissions.

  • Cryptography and key management — counter rotation, anti-replay windows, and authenticated encryption — denies replayed traffic acceptance.

  • Relay-protection (replay-resistant authentication) for remote and bus connections is the named control against re-transmission of captured traffic.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, EX-0001 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.