All techniques
EX-0008
ST0004Execution

Time Synchronized Execution

Description

Malicious logic is arranged to run at precise times derived from onboard clocks or distributed time sources. The trigger may be absolute or relative. Spacecraft commonly maintain multiple clocks and counters and schedule autonomous sequences against them. An attacker leverages this machinery to ensure effects occur during tactically advantageous windows. Time-based execution reduces exposure, simplifies coordination across assets, and makes reproduction difficult in lab settings that lack the same temporal context.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(l)
    addresses
    moderate
    derived

    Manufacturer logging/monitoring obligation surfaces anomalous activations keyed to time triggers; logging must capture time-correlation evidence that supports detection of dormant-trigger malicious logic.

  • craAnnex I, Part II, (3)
    addresses
    moderate
    derived

    Effective and regular security tests and reviews surface time-keyed dormant logic before release; behavior-state and time-fast-forward testing fall within (3) scope.

  • nis2-implAnnex 3.2.6
    addresses
    moderate
    derived

    Synchronized time sources are required for log correlation; the same time-sync discipline that supports forensic correlation also helps surface anomalous time-keyed activations across subsystems.

  • nis2-implAnnex 6.9.1
    addresses
    moderate
    derived

    Time-synchronized triggers are dormant malicious logic; protection-against-malicious-and-unauthorized-software obligations cover detection of code that activates on time-of-day or elapsed-time conditions.

ENISA controls

  • Vulnerability management is a relevant security process, but its scope is collecting and evaluating known technical vulnerabilities, not detecting the bespoke time-triggered implant EX-0008 uses, so addresses rather than mitigates.

  • End-to-end testing with negative/abuse cases catches time-keyed conditional behaviour not exercised under nominal regression suites.

  • Long-duration testing (30+ days) is explicitly aimed at race conditions and time-based attacks, the defining property of EX-0008.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, EX-0008 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.