All techniques
EX-0014.02
ST0004Execution
sub-technique

Bus Traffic Spoofing

Parent: EX-0014

Description

Here the adversary forges messages on internal command/data paths (e.g., 1553, SpaceWire, CAN, custom). By emitting frames with valid identifiers, addresses, and timing, the attacker can make subscribers accept actuator setpoints, power switch toggles, mode changes, or housekeeping values that originated off-path. Because many consumers act on “latest value wins” or on message cadence, forged traffic can mask real publishers, starve critical topics, or force handlers to execute unintended branches. Gateways that translate between networks amplify impact: a spoofed message on one side can propagate to multiple domains as legitimate payload. Outcomes include misdelivered commands, silent configuration drift, and control loops chasing phantom stimuli, all while bus monitors show protocol-conformant traffic.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(d)
    addresses
    high
    derived

    Authentication on internal bus interfaces (1553, SpaceWire, custom) is the manufacturer-side defense against forged-frame injection from arbitrary nodes.

  • craAnnex I, Part I, (2)(f)
    addresses
    high
    derived

    Integrity protection on bus traffic resists forged-frame acceptance by subscribers.

  • craAnnex I, Part I, (2)(j)
    addresses
    moderate
    derived

    Limited attack surfaces include bus-segment trust domains; manufacturers must enforce origin restrictions on bus-message production.

  • eu-space-actArt. 84(2)
    addresses
    high
    direct

    Internal-bus message authentication is part of 84(2)'s Annex VII point 5.1 compliance — bus traffic with valid identifiers from unauthorized sources must be filtered.

  • eu-space-actArt. 84(3)
    addresses
    high
    direct

    84(3)'s only-authorized-devices-communicate rule governs internal-bus participants — preventing forged frames from being honored regardless of identifier validity.

  • nis2Art. 21(2)(b)
    addresses
    moderate
    derived

    Bus anomalies (silent configuration drift, control-loops chasing phantom stimuli, cross-domain propagation through gateways) are detectable via integrity monitoring; Art. 21(2)(b)'s incident-handling capability must surface them despite protocol-conformant traffic.

  • nis2Art. 21(2)(h)
    addresses
    moderate
    direct

    Art. 21(2)(h) obliges cryptography policies and procedures that can extend to bus message authentication; it addresses bus-traffic spoofing by requiring those measures where the bus supports them, while the deployed MACs and per-publisher key separation, not the policy article, are what reject forged frames with otherwise-valid identifiers.

  • nis2-implAnnex 6.7.1
    addresses
    moderate
    derived

    Internal command/data buses are part of the entity's network estate; network-security obligations cover the protection of bus traffic from forged-frame injection through authentication, source restriction and segmentation.

  • nis2-implAnnex 6.8.1
    addresses
    moderate
    derived

    Bus segmentation between high-trust and low-trust subsystems bounds where forged bus frames can travel and which subscribers consume them.

ENISA controls

  • Access-based network segmentation isolating mission-critical functions limits gateway-amplified spoofed-message propagation.

  • On-board message encryption with bus-level authentication directly defeats spoofed bus traffic with forged identifiers and addresses.

  • Process-ID whitelisting on the satellite bus restricts which IDs can publish to subscriber topics, defeating spoofed publishers.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, EX-0014.02 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.