All techniques
EX-0013.01
ST0004Execution
sub-technique

Valid Commands

Parent: EX-0013

Description

Here the adversary saturates paths with legitimate telecommands or bus messages so the spacecraft burns scarce resources honoring them. Inputs may be innocuous (no-ops, time queries, telemetry requests) or low-risk configuration edits, but at scale they consume command handler cycles, fill queues, generate events and logs, trigger acknowledgments, and provoke downstream work in subsystems (e.g., repeated state reports, mode toggles, or file listings). On internal buses, valid actuator or housekeeping messages replayed at high rate can starve higher-priority publishers or cause control laws to chase stale stimuli. Because the traffic is syntactically correct, and often contextually plausible, the system attempts to process it rather than discard it early, increasing CPU usage, memory pressure, and power draw. Consequences include delayed or preempted legitimate operations, transient loss of commandability, and knock-on FDIR activity as deadlines slip and telemetry appears inconsistent.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(d)
    addresses
    moderate
    derived

    Authentication procedures with rate-limiting, per-counter validation and identity binding reduce the resource cost of valid-command flooding by enabling cheap rejection.

  • craAnnex I, Part I, (2)(h)
    addresses
    high
    derived

    Availability obligation covers valid-command flooding; products must absorb or shed legitimate-but-saturating command traffic without losing essential functions.

  • eu-space-actArt. 83(1)
    addresses
    high
    direct

    Valid-but-excessive command flooding requires anomaly detection on volume and pattern — 83(1)'s continuous monitoring obligation surfaces these saturation patterns when nominal-shape volumetrics deviate.

  • eu-space-actArt. 84(2)
    addresses
    moderate
    direct

    Rate/size limits on the command path are network-and-information-system properties under 84(2)'s Annex VII point 5.1 scope.

  • nis2Art. 21(2)(b)
    addresses
    high
    derived

    Streams of valid-but-volume-anomalous commands (no-ops, telemetry requests, repeated state reports) are detectable as incidents the entity's incident-handling capability under Art. 21(2)(b) must surface from baseline command-volume monitoring.

  • nis2Art. 21(2)(i)
    addresses
    moderate
    direct

    Per-session rate limits, per-account quotas, and queue-priority configuration are the access-control discipline Art. 21(2)(i) governs — bounding the resource impact a single legitimate-but-misused identity can produce.

  • nis2-implAnnex 11.6.1
    addresses
    moderate
    derived

    Authentication procedures with rate-limiting and per-counter validation reduce the resource cost of valid-command flooding because each replay or duplicate command is rejected at minimal expense.

  • nis2-implAnnex 3.2.1
    addresses
    moderate
    derived

    Monitoring-and-logging procedures must surface elevated valid-command rates and unusual operator command-history patterns, which are the observable signatures of valid-command flooding.

ENISA controls

  • On-board IDS/IPS surfaces excessive cadence of valid commands and selects safe countermeasures.

  • Critical-telemetry-points monitoring for command counters and command-modes detects abusive valid-command volume.

  • Peak-throughput sizing for command pathways under cyber-relevant cases (high-volume valid traffic) is the named defense against valid-command flooding.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, EX-0013.01 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.