All techniques
IA-0008.01
ST0003Initial Access
sub-technique

Rogue Ground Station

Parent: IA-0008

Description

Adversaries may field their own ground system, transportable or fixed, to transmit and receive mission-compatible signals. A typical setup couples steerable apertures and GPS-disciplined timing with SDR/modems configured for the target’s bands, modulation/coding, framing, and beacon structure. Using pass schedules and Doppler/polarization predictions, the actor crafts over-the-air traffic that appears valid at the RF and protocol layers.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(d)
    mitigates
    high
    derived

    Manufacturer-implemented authentication on the uplink defeats rogue ground stations: per-counter MAC verification rejects commands lacking valid keys regardless of transmit power or geometry.

  • eu-space-actArt. 84(3)
    addresses
    high
    direct

    Adversary-fielded ground stations transmitting mission-compatible signals are exactly what 84(3)'s only-authorized-devices rule excludes.

  • eu-space-actArt. 85(2)
    addresses
    moderate
    direct

    Rogue ground station (primary: Art. 85(3)) cascades to 85(2) — key-lifecycle discipline ensures rogue stations cannot acquire valid keys through stale or improperly disposed material.

  • eu-space-actArt. 85(3)
    addresses
    high
    direct

    End-to-end authentication under 85(3)(a) between satellite control centres and space segment is the cryptographic posture that defeats rogue-station injection regardless of RF correctness.

  • nis2Art. 21(2)(h)
    addresses
    high
    direct

    Art. 21(2)(h) requires cryptography policies and procedures covering uplink authentication; it addresses rogue-ground-station commanding by mandating those measures, while the deployed uplink authentication, not the policy obligation, is what defeats a rogue station's syntactically valid traffic.

  • nis2-implAnnex 11.6.1
    mitigates
    high
    derived

    A rogue ground station with steerable apertures and accurate timing is defeated by uplink command authentication binding commands to per-counter MACs the rogue cannot forge without valid keys.

  • nis2-implAnnex 6.7.1
    addresses
    moderate
    derived

    Network-security obligations apply to RF-link protection, including the cryptographic and protocol measures that resist injection from arbitrary transmitters.

ENISA controls

  • Communications security with imitative-deception detection on RF signal parameters surfaces transmissions that mimic the operator's emissions.

  • Cryptography and key management restricts encryption keys to authorised endpoints, so a rogue ground station cannot issue accepted commands without compromised keys.

  • Bidirectional cryptographic authentication on commands defeats traffic from an adversary-fielded ground station that lacks mission keys, regardless of RF/protocol fidelity.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, IA-0008.01 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.