All techniques
EX-0013
ST0004Execution

Flooding

Description

Flooding overwhelms a communication or processing path by injecting traffic at rates or patterns the system cannot comfortably absorb. In space contexts this can occur across layers: RF/optical links (continuous carriers, wideband noise, or protocol-shaped bursts); link/protocol layers (valid-looking frames at excessive cadence); application layers (command and telemetry messages that saturate parsers and queues); and internal vehicles buses where repeated messages starve critical publishers. Effects range from outright denial of service, dropped commands, lost telemetry, missed windows, to subtler corruption, such as out-of-order processing, watchdog trips, or autonomy entering protective modes due to backlogged health data. Secondary impacts include power and thermal strain as decoders, modems, or software loops spin at maximum duty, storage filling from retries, and control loops jittering when their messages are delayed. Timing matters: floods during handovers, maneuvers, or safing transitions can magnify consequences because margins are thinnest.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(h)
    addresses
    high
    direct

    Availability obligation explicitly references resilience and mitigation against denial-of-service attacks; flooding is the canonical DoS class governed by (2)(h).

  • craAnnex I, Part I, (2)(i)
    addresses
    moderate
    derived

    Manufacturer obligation to minimise the negative impact of products on availability of services applies to flooding scenarios where products participate in or amplify DoS effects.

  • eu-space-actArt. 84(2)
    addresses
    moderate
    direct

    Flooding attacks the availability properties of network-and-information-system; 84(2)'s Annex VII point 5.1 compliance includes rate limiting and queue-management against saturation.

  • eu-space-actArt. 87(2)
    addresses
    moderate
    direct

    87(2)'s response-and-recovery plans cover the operator's discipline in containing flood-induced denial — fallback, rate shaping, and quick recovery.

  • eu-space-actArt. 87(4)
    addresses
    moderate
    direct

    Flooding response (primary: Art. 87(2) BCDR) cascades to 87(4) — staff implementing DoS containment and rate-limit fallback need role-appropriate training.

  • nis2Art. 21(2)(b)
    addresses
    high
    derived

    Excess traffic at any layer (RF/optical, link, application, internal-bus) producing dropped commands, lost telemetry, missed windows, and FDIR entries is a paradigmatic incident the entity's incident-handling capability under Art. 21(2)(b) must detect, contain, and document.

  • nis2Art. 21(2)(c)
    addresses
    moderate
    direct

    Service availability under volumetric attack — backup paths, throttling regimes, and recovery procedures — falls under business continuity, backup management, and crisis management under Art. 21(2)(c).

  • nis2Art. 23(1)
    triggers obligation
    moderate
    direct

    Sustained flooding causing severe operational disruption to the entity's services meets Art. 23(3)(a) and triggers Art. 23(1) reporting.

  • nis2Art. 23(2)
    addresses
    high
    derived

    Primary mapping to Art. 23(1) treats resource-flooding (DoS-class) attacks as a significant incident. Art. 23(2) timing applies once that obligation is triggered.

  • nis2Art. 23(3)
    relates to
    moderate
    derived

    Primary mapping to Art. 23(1) treats flooding as significant. Art. 23(3) is met by the operational-disruption test directly; cross-border impact applies when the flooded service supports users across Member States.

  • nis2Art. 23(4)
    addresses
    high
    derived

    Primary mapping to Art. 23(1) drives Art. 23(4) deadlines. For flooding, the 24-hour early warning is the first reporting milestone since the attack is observable in real time but its scope and persistence are not.

  • nis2-implAnnex 13.2.1
    addresses
    moderate
    derived

    RF-layer flooding (in-band noise injection at the receiver) is a physical-layer threat the protection-against-physical-and-environmental-threats obligation covers through link-budget design, antenna pattern shaping and signal hardening.

  • nis2-implAnnex 3.2.1
    addresses
    high
    derived

    Monitoring-and-logging procedures must surface anomalous traffic volume, command rates and parser-load events, which are the observable signatures of flooding attacks.

  • nis2-implAnnex 6.7.1
    addresses
    moderate
    derived

    Network-security obligations cover protection of links and processing paths from saturation; rate limiting, traffic shaping and ingress filtering at gateways are the network-security controls that absorb or shed flooding traffic.

ENISA controls

  • Intrusion detection and prevention with response capability detects flooding patterns and selects safe countermeasures (rate limiting, isolation).

  • Capacity planning for peak throughput including cyber/counterspace cases is the explicit defense against flooding-induced resource exhaustion.

  • Ground-segment redundancy with fully backed up servers and load balancers enables shifting throughput when one site is flooded.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, EX-0013 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.