All techniques
EX-0001.02
ST0004Execution
sub-technique

Bus Traffic Replay

Parent: EX-0001

Description

Instead of the RF path, the attacker targets internal command/data handling by injecting or retransmitting messages on the spacecraft bus (e.g., 1553, SpaceWire, custom). Because many subsystems act on the latest message or on message rate rather than on uniqueness, a flood of historical yet well-formed frames can consume bandwidth, starve critical publishers, or cause subsystems to perform the same action repeatedly. Secondary effects include stale sensor values being re-consumed, watchdog timers being reset at incorrect intervals, and autonomy rules misclassifying the situation due to out-of-order but valid-looking events. On time-triggered or scheduled buses, replaying at precise offsets can collide with or supersede legitimate messages, steering system state without changing software. The goal is to harness the bus’s determinism, repeating prior internal stimuli to recreate prior effects or to induce resource exhaustion.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(d)
    addresses
    high
    derived

    Authentication on internal command/data buses (1553, SpaceWire, custom) is the manufacturer-side control that resists bus-traffic replay; products should enforce origin authentication on bus messages.

  • craAnnex I, Part I, (2)(f)
    addresses
    high
    derived

    Integrity protection on bus traffic prevents replayed messages from being accepted by subsystems that subscribe to specific message classes.

  • craAnnex I, Part I, (2)(j)
    addresses
    moderate
    derived

    Limited attack surfaces apply to internal bus interfaces; manufacturers must constrain which transmit nodes can produce traffic for which subscribers.

  • eu-space-actArt. 84(2)
    addresses
    high
    direct

    Internal-bus replay attacks the network-and-information-system properties under 84(2) — Annex VII point 5.1 requirements include integrity and authentication on internal buses.

  • eu-space-actArt. 84(3)
    addresses
    moderate
    direct

    84(3)'s only-authorized-devices rule extends to internal bus participants — limiting which on-board nodes can replay or inject historical traffic.

  • nis2Art. 21(2)(b)
    addresses
    moderate
    derived

    Bus-traffic anomalies — duplicate frames, rate-cap exhaustion, watchdog-reset misalignment — are detectable as incidents the entity's incident-handling capability under Art. 21(2)(b) must surface from internal-bus telemetry.

  • nis2-implAnnex 6.7.1
    addresses
    moderate
    derived

    Internal command/data buses (1553, SpaceWire, custom) are part of the network-and-information-systems estate; network-security measures apply to the protection of bus traffic from arbitrary injection or replay.

  • nis2-implAnnex 6.8.1
    addresses
    moderate
    derived

    Segmentation between bus segments (and between the bus and crosslink/payload-facing functions) bounds where replayed bus traffic can travel and which subsystems it reaches.

ENISA controls

  • Bus-level authenticated encryption raises the cost of bus replay but does not interdict EX-0001.02's dominant scope. Many bus subsystems act on the latest message or on message rate rather than on uniqueness, and time-triggered buses resist anti-replay, so replayed well-formed frames can still drive resource exhaustion and determinism abuse. Cryptography and key management is in-domain but is not the operative interdiction of this technique, so at the Cryptography and Crypto Key Management control the relationship is addresses, not mitigates.

  • On-board message encryption is relevant to spacecraft-bus message protection, but the confidentiality excerpt does not provide the anti-replay authentication needed to counter bus-traffic replay.

  • Replay-resistant authentication on bus connections is the named defense for retransmission of internal command/data-handling messages.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, EX-0001.02 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.