All techniques
EX-0012.03
ST0004Execution
sub-technique

Memory Write/Loads

Parent: EX-0012

Description

The adversary uses legitimate direct-memory commands or load services to place chosen bytes at chosen addresses. Many spacecraft support raw read/write operations, block loads into RAM or non-volatile stores, and table/file loaders that copy content into working memory. With knowledge of address maps and data structures, an attacker can patch function pointers or vtables, alter limit and configuration records, seed scripts or procedures into interpreter buffers, adjust DMA descriptors, or overwrite portions of executable images resident in RAM. Loads may be sized and paced to fit link and queue constraints, then activated by a subsequent command, mode change, or natural reference by the software.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(d)
    addresses
    high
    derived

    Authentication obligations bound who can issue raw memory operations; manufacturers must constrain memory-write authority via factor-bound auth.

  • craAnnex I, Part I, (2)(f)
    addresses
    high
    derived

    Integrity protection on stored data and programs resists arbitrary memory-load manipulation; signed-image enforcement and write-protected memory regions are manufacturer-side defenses.

  • craAnnex I, Part I, (2)(j)
    addresses
    moderate
    derived

    Limited attack surfaces include raw memory-write interfaces; manufacturers must disable or constrain such interfaces post-deployment.

  • eu-space-actArt. 81(3)
    addresses
    high
    direct

    Direct memory write/load commands are precisely the critical-function-access scenario 81(3)(b) restricts — only authorized identities should be able to invoke raw memory operations.

  • eu-space-actArt. 84(3)
    addresses
    moderate
    direct

    84(3)'s only-authorized-devices rule governs which sources can issue memory-load commands — preventing unauthorized writes via the command path.

  • nis2Art. 21(2)(h)
    addresses
    moderate
    inferred

    Signed memory loads and authenticated block transfers are cryptographic mechanisms that prevent chosen-byte writes at chosen addresses via legitimate transfer mechanisms, but they do not cover direct memory tampering by an adversary with write access, where the operative control is memory protection and access control. The CIR (EU) 2024/2690 Annex assigns those system-integrity and access controls to section 6, not to the section 9 cryptography requirements. At NIS2 Art. 21(2)(h) the relationship is addresses.

  • nis2Art. 21(2)(i)
    addresses
    high
    direct

    Direct-memory write/load services, block loaders, and file-loaders that copy content into working memory are precisely the access-controlled functions Art. 21(2)(i)'s access-control + asset-management obligation governs.

  • nis2-implAnnex 11.3.1
    addresses
    high
    derived

    Memory-write authority is privileged; the privileged-account policy bounds who can issue raw memory operations and applies the review obligations that detect misuse.

  • nis2-implAnnex 3.2.1
    addresses
    moderate
    derived

    Monitoring-and-logging procedures must capture memory-write commands and post-effect telemetry, which are the observable signatures of malicious memory loading.

  • nis2-implAnnex 6.4.1
    addresses
    high
    derived

    Direct memory-write/load operations are change-management events that must follow documented procedures; emergency procedures still require documentation and post-event review.

ENISA controls

  • Process-ID whitelisting for satellite-bus and payload-firmware commanding restricts which IDs can issue arbitrary memory writes.

  • Integrity-checking mechanisms validate mission software and firmware, the targets of memory write/load operations EX-0012.03 issues.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, EX-0012.03 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.