All techniques
EX-0012.02
ST0004Execution
sub-technique

Internal Routing Tables

Parent: EX-0012

Description

Threat actors may rewrite the maps that tell software where to send and receive things. In publish/subscribe or message-queued flight frameworks, tables map message IDs to subscribers, opcodes to handlers, and pipes to processes; at interfaces, address/port maps define how traffic traverses bridges and gateways (e.g., SpaceWire node/port routes, 1553 RT/subaddress mappings, CAN IDs). By altering these structures, commands can be misdelivered, dropped, duplicated, or routed through unintended paths; telemetry can be redirected or blackholed; and handler bindings can be swapped so an opcode triggers the wrong function. Schedule/routing hybrids, used to sequence activities and distribute results, can be edited to reorder execution or to create feedback loops that occupy bandwidth and processor time. The result is control over who hears what and when, achieved by changing the lookup tables that underpin command/telemetry distribution rather than the code that processes them.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(f)
    addresses
    high
    derived

    Integrity protection on internal routing tables resists rewrites of message-ID-to-handler mappings that would re-route traffic to attacker-controlled subscribers.

  • craAnnex I, Part I, (2)(j)
    addresses
    moderate
    derived

    Limited attack surfaces define which trust domains can publish to which subscribers; manufacturers must enforce these boundaries in routing-table policy.

  • eu-space-actArt. 84(2)
    addresses
    high
    direct

    Internal routing tables (1553 RT/SA, SpaceWire node/port, CAN ID maps) are network-and-information-system configuration covered by 84(2)'s Annex VII point 5.1 integrity requirements.

  • nis2Art. 21(2)(b)
    addresses
    moderate
    derived

    Silent rerouting (commands misdelivered, telemetry blackholed, handler swaps) produces subtle traffic-pattern anomalies; Art. 21(2)(b)'s incident-handling capability must surface them via routing-integrity baselines.

  • nis2Art. 21(2)(i)
    addresses
    moderate
    direct

    Pub/sub maps, opcode-handler bindings, and bus routing tables are access-controlled configuration assets; Art. 21(2)(i)'s access-control + asset-management obligation governs the edits that reshape control and visibility.

  • nis2-implAnnex 6.4.1
    addresses
    moderate
    derived

    Internal routing-table rewrites are configuration changes governed by change-management procedures; the implementing regulation requires controlled modification with documented review.

  • nis2-implAnnex 6.8.1
    addresses
    moderate
    derived

    Network segmentation defines the trust boundaries that internal routing tables enforce; segmentation discipline constrains the scope of damage from a routing-table rewrite.

ENISA controls

  • Routing/subscriber tables are configuration items whose baseline must be established, documented, monitored, and reviewed under configuration management.

  • Access-based network segmentation isolating mission-critical functionality limits the reach of misdelivered traffic produced by routing-table modification.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, EX-0012.02 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.