All techniques
EX-0014.01
ST0004Execution
sub-technique

Time Spoof

Parent: EX-0014

Description

Time underpins sequencing, anti-replay, navigation filtering, and data labeling. An attacker that forges or biases the time seen by onboard consumers can reorder stored command execution, break timetag validation, desynchronize counters, and misalign estimation windows. Spoofing vectors include manipulating the distributed time service, introducing a higher-priority/cleaner time source (e.g., GNSS-derived time), or crafting messages that cause clock discipline to slew toward attacker-chosen values. Once time shifts, autonomous routines keyed to epochs, wheel unloads, downlink starts, heater schedules, fire early/late or not at all, and telemetry appears inconsistent to ground analysis. The signature is correct-looking time metadata that steadily or abruptly departs from truth, driving downstream logic to act at the wrong moment.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(d)
    addresses
    moderate
    derived

    Authentication on time-distribution paths (signed PTP/NTP, authenticated cross-link time tags) reduces the success of forged time inputs.

  • craAnnex I, Part I, (2)(f)
    addresses
    high
    derived

    Integrity protection on time-distribution inputs resists biased or forged time tags that would reorder execution and break anti-replay counters.

  • eu-space-actArt. 84(2)
    addresses
    moderate
    direct

    Time integrity is foundational to network-and-information-system; 84(2)'s Annex VII point 5.1 covers protection of distributed-time service.

  • eu-space-actArt. 85(2)
    addresses
    moderate
    inferred

    Art. 85(2)'s key-lifecycle policy is crypto-domain-relevant to EX-0014.01, but key lifecycle does not interdict time-source spoofing; authenticated time distribution would be the interdicting mechanism.

  • nis2Art. 21(2)(h)
    addresses
    moderate
    direct

    Art. 21(2)(h) requires cryptography policies and procedures covering authenticated time distribution; it addresses time spoofing by mandating those measures, while the deployed authenticated time sources and integrity-protected disciplining, not the policy article, are what defeat the time-bias attack.

  • nis2Art. 21(2)(i)
    addresses
    moderate
    direct

    Time-distribution services, disciplining-source selection, and clock-register access are access-controlled functions; Art. 21(2)(i)'s access-control + asset-management obligation governs who can write them.

  • nis2-implAnnex 11.6.1
    addresses
    moderate
    derived

    Authentication on time-distribution paths (signed PTP/NTP, authenticated cross-link time tags) reduces the success of forged time inputs to onboard consumers.

  • nis2-implAnnex 3.2.6
    addresses
    moderate
    derived

    The synchronized-time-source obligation requires ensuring all systems have reliable time bases; that obligation is exactly what time-spoofing attempts to subvert, and the underlying time-source architecture is the defense.

ENISA controls

  • Configuration management of distributed time-service settings detects unauthorised slewing toward attacker-chosen values.

  • Resilient PNT with GNSS authentication and fault-tolerant time sourcing across SpaceWire to ~1 µs is the named defense against time spoofing.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, EX-0014.01 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.