All techniques
EX-0012.12
ST0004Execution
sub-technique

System Clock

Parent: EX-0012

Description

Spacecraft maintain multiple time bases and distribute time to schedule sequences, validate timetags, manage anti-replay counters, and align navigation/attitude processing. By writing to clock registers, altering time-distribution services, switching disciplining sources, or biasing oscillator parameters, an adversary can skew these references. Effects include reordering or prematurely firing stored command sequences, invalidating timetag checks, desynchronizing counters used by authentication or ranging, misaligning estimator windows, and corrupting timestamped payload data. Even small offsets can accumulate into observable misbehavior when autonomy and scheduling depend on tight temporal guarantees. The result is execution that happens at the wrong moment, or not at all, because the system’s notion of “now” has been shifted.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(f)
    addresses
    high
    derived

    Integrity protection on system-clock state and time-distribution sources resists clock-write tampering with anti-replay counters and time-tag validation.

  • craAnnex I, Part I, (2)(l)
    addresses
    moderate
    derived

    Logging obligation requires reliable time references for forensic correlation; clock-tampering surfaces as anomaly in cross-source disagreement captured in logs.

  • eu-space-actArt. 84(2)
    addresses
    high
    direct

    System clock state is foundational to integrity of network-and-information-system data; 84(2)'s Annex VII point 5.1 covers time-distribution integrity.

  • eu-space-actArt. 85(2)
    addresses
    moderate
    inferred

    Art. 85(2)'s key-lifecycle policy is crypto-domain-relevant to clock manipulation, but does not interdict time-source manipulation; authenticated time distribution would interdict.

  • nis2Art. 21(2)(h)
    addresses
    moderate
    direct

    Anti-replay counters and timetag validation under cryptography policy at Art. 21(2)(h) depend on a stable, authenticated time base; the obligation requires that time-distribution services be integrity-protected against the bias attack the technique describes.

  • nis2Art. 21(2)(i)
    addresses
    moderate
    direct

    Clock registers, time-distribution services, and disciplining-source configuration are access-controlled assets; Art. 21(2)(i)'s access-control + asset-management obligation governs which roles can write them.

  • nis2-implAnnex 3.2.6
    addresses
    high
    direct

    Synchronized time-source obligations (Annex 3.2.6) underpin log correlation and anti-replay; the same discipline that maintains time-source integrity also surfaces unauthorized clock modifications across subsystems.

  • nis2-implAnnex 6.4.1
    addresses
    moderate
    derived

    Clock writes and time-base reconfiguration are change-management events with significant downstream effects on sequencing, anti-replay and navigation; documented procedures must govern such modifications.

ENISA controls

  • Configuration management of system-clock baselines detects unauthorised slewing or epoch changes.

  • Resilient PNT including fault-tolerant authoritative time sourcing is the named defense against unauthorised system-clock modifications.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, EX-0012.12 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.