All techniques
IA-0008
ST0003Initial Access

Rogue External Entity

Description

Adversaries obtain a foothold by interacting with the spacecraft from platforms outside the authorized ground architecture. A “rogue external entity” is any actor-controlled transmitter or node, ground, maritime, airborne, or space-based, that can radiate or exchange traffic using mission-compatible waveforms, framing, or crosslink protocols. The technique exploits the fact that many vehicles must remain commandable and discoverable over wide areas and across multiple modalities. Using public ephemerides, pass predictions, and knowledge of acquisition procedures, the actor times transmissions to line-of-sight windows, handovers, or maintenance periods. Initial access stems from presenting traffic that the spacecraft will parse or prioritize: syntactically valid telecommands, crafted ranging/acquisition exchanges, crosslink service advertisements, or payload/user-channel messages that bridge into the command/data path.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(d)
    mitigates
    moderate
    derived

    Authentication obligations on the spacecraft uplink (cryptographic command authentication, counters, replay protection) reduce a rogue external transmitter to noise; the product manufacturer must implement these mechanisms regardless of the legitimate ground architecture.

  • eu-space-actArt. 84(3)
    addresses
    high
    direct

    Rogue external entities are the canonical case 84(3)'s only-authorized-devices-communicate-with-control-systems rule defends against — any external transmitter outside the approved set must be filtered.

  • eu-space-actArt. 85(2)
    addresses
    moderate
    direct

    Rogue-external-entity (primary: Art. 85(3)) cascades to 85(2) — proper key lifecycle ensures only authorized identities hold valid keys.

  • eu-space-actArt. 85(3)
    addresses
    high
    direct

    85(3)(a)'s end-to-end-authentication-between-SCC-and-space-segment is the cryptographic discipline that defeats traffic from any node not holding valid mission credentials.

  • nis2Art. 21(2)(h)
    addresses
    moderate
    direct

    Art. 21(2)(h) obliges cryptography policies and procedures covering uplink and crosslink authentication; it addresses rogue external commanding by requiring mutual authentication, while the deployed authentication, not the policy article, is what stops a syntactically valid transmission from an unauthorised platform being acted on as a telecommand.

  • nis2Art. 21(2)(j)
    addresses
    moderate
    inferred

    Scoped to its cyber authentication-defeat core, IA-0008 (a rogue external entity presenting mission-compatible traffic) triggers NIS2 Art. 21(2)(j): correct authentication of mission traffic rejects an origin that lacks valid credentials. The clearly physical strands of the technique (RF-geometry exploitation, directed-energy, and kinetic counterspace effects) fall outside the Article 21(2) cyber-risk measures and are excluded from this mapping. The jamming and spoofing electronic-warfare strand is not decided here; it is deferred to the E/F counterspace-scope determination, consistent with the IA-0008.03 hold.

  • nis2-implAnnex 11.6.1
    mitigates
    high
    derived

    Secure-authentication procedures on the uplink (cryptographic command authentication, counters, replay protection) reduce a rogue external transmitter to noise — without valid authentication tags the spacecraft does not accept commands.

  • nis2-implAnnex 6.7.1
    addresses
    moderate
    derived

    Network-security measures cover the air interface as part of the entity's network-and-information-systems estate; protection of the link from injection is a network-security obligation.

ENISA controls

  • Communications security with imitative-deception rejection identifies and rejects deliberate attempts to imitate authorised transmissions.

  • Transmission security counters interception and communications deception that rogue external entities use to present syntactically valid traffic.

  • Authentication of every command session — only authenticated stations can establish a commanding link — directly defeats rogue external-entity transmissions.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, IA-0008 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.