All techniques
IA-0004
ST0003Initial Access

Secondary/Backup Communication Channel

Description

Adversaries pursue alternative paths to the spacecraft that differ from the primary TT&C in configuration, monitoring, or authentication. Examples include backup MOC/ground networks, contingency TT&C chains, maintenance or recovery consoles, low-rate emergency beacons, and secondary receivers or antennas on the vehicle. These channels exist to preserve commandability during outages, safing, or maintenance; they may use different vendors, legacy settings, or simplified procedures. Initial access typically pairs reconnaissance of failover rules with actions that steer operations onto the backup path, natural events, induced denial on the primary, or simple patience until scheduled tests and handovers occur. Once traffic flows over the alternate path, the attacker leverages its distinct procedures, dictionaries, or rate/size limits to introduce commands or data that would be harder to inject on the primary.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(d)
    addresses
    high
    derived

    Manufacturer authentication obligations apply uniformly to primary and secondary/backup channels; the product must enforce equivalent authentication on contingency TT&C, beacons and emergency commanding paths.

  • craAnnex I, Part I, (2)(j)
    addresses
    moderate
    derived

    Limited attack surfaces apply to secondary/backup interfaces; manufacturers should design backup channels to be activated only when needed and locked down by default.

  • eu-space-actArt. 84(2)
    addresses
    high
    direct

    Backup/contingency channels are network and information systems within 84(2)'s scope — the requirement that they comply with Annex VII point 5.1 covers their security posture, not just the primary TT&C.

  • eu-space-actArt. 84(3)
    addresses
    high
    direct

    84(3)'s only-authorized-devices-communicate rule applies regardless of whether the path is primary or secondary — backup channels need the same authentication discipline.

  • eu-space-actArt. 87(2)
    addresses
    moderate
    inferred

    Art. 87(2)'s response and recovery plans are domain-relevant to backup-channel operations, but govern failover discipline, not interdiction of the backup-path access vector; authenticated backup receivers would interdict.

  • eu-space-actArt. 87(4)
    addresses
    moderate
    direct

    Backup-channel initial-access response (primary: Art. 87(2) BCDR) cascades to 87(4) — staff executing failover to backup channels need training to detect adversary-driven misuse of contingency paths.

  • nis2Art. 21(2)(b)
    addresses
    high
    derived

    Sparsely supervised secondary paths producing unexpected commanding traffic during failover or maintenance windows are detectable incidents; Art. 21(2)(b)'s incident-handling capability must extend monitoring across all paths, not just the primary.

  • nis2Art. 21(2)(c)
    addresses
    moderate
    direct

    Backup management and crisis-management procedures under Art. 21(2)(c) are how the entity designs and exercises secondary/contingency communication channels — the obligation that should preserve security parity, not relax it for availability.

  • nis2Art. 21(2)(h)
    addresses
    moderate
    inferred

    Authentication parity defeats forged-command injection on a weakly-authenticated alternate path, but it does not stop exploitation of the alternate path itself, where the operative control is consistent access control across paths. Under the strict bar the cryptographic control covers the forgery vector but not the dominant cross-path access-control residual, so at NIS2 Art. 21(2)(h) the relationship is addresses.

  • nis2-implAnnex 11.6.1
    addresses
    high
    derived

    Secure authentication on backup paths must match the primary; the implementing regulation requires authentication strength appropriate to the asset, with no carve-out for contingency channels.

  • nis2-implAnnex 3.2.1
    addresses
    moderate
    derived

    Monitoring-and-logging procedures must cover backup paths because they are precisely the channels less frequently exercised and most likely to harbour unnoticed adversary presence.

  • nis2-implAnnex 6.7.1
    addresses
    moderate
    derived

    Backup TT&C and contingency MOC paths are part of the entity's network-and-information-systems estate; network-security obligations apply equally to the primary and the alternate, including cross-strapped paths.

ENISA controls

  • Communications security on backup TT&C chains preserves the same secure-protocol posture, denying the differential exploitation IA-0004 relies on.

  • Cryptographic bidirectional authentication on every commanding session — primary or backup — prevents IA-0004 from exploiting weaker authentication on the alternate path.

  • System-redundancy planning is the operational context in which backup channels exist; their security posture should match the primary, addressing the gap IA-0004 exploits.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, IA-0004 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.