All techniques
IA-0008.02
ST0003Initial Access
sub-technique

Rogue Spacecraft

Parent: IA-0008

Description

Adversaries may employ their own satellite or hosted payload to achieve proximity and a privileged RF geometry. After phasing into the appropriate plane or drift orbit, the rogue vehicle operates as a local peer: emitting narrow-beam or crosslink-compatible signals, relaying user-channel traffic that the target will honor, or advertising services that appear to originate from a trusted neighbor. Close range reduces path loss and allows highly selective interactions, e.g., targeted spoofing of acquisition exchanges, presentation of crafted routing/time distribution messages, or injection of payload tasking that rides established inter-satellite protocols. The rogue platform can also perform spectrum and protocol reconnaissance in situ, refining message formats and timing before attempting first execution.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(d)
    mitigates
    moderate
    derived

    Authentication on crosslink and proximity-domain interfaces converts a rogue spacecraft into an unauthenticated peer; manufacturer-mandated auth makes RF geometry insufficient without valid keys.

  • craAnnex I, Part I, (2)(j)
    addresses
    moderate
    derived

    Limited attack surfaces on proximity-facing interfaces bound what a rogue-spacecraft peer can interact with even when within RF range.

  • eu-space-actArt. 84(3)
    addresses
    high
    direct

    Adversary spacecraft emitting crosslink-compatible signals or relaying user traffic must be filtered by 84(3)'s only-authorized-devices rule on inter-satellite links.

  • eu-space-actArt. 85(1)
    addresses
    high
    direct

    85(1)'s cryptographic concept must define authentication for crosslink and proximity-link contexts so that a rogue spacecraft cannot present itself as a trusted neighbor.

  • eu-space-actArt. 85(2)
    addresses
    moderate
    direct

    Rogue spacecraft (primary: Art. 85(1)) cascades to 85(2) — crosslink/proximity key lifecycle limits rogue-vehicle ability to present valid credentials.

  • nis2Art. 21(2)(h)
    addresses
    moderate
    direct

    Art. 21(2)(h) obliges cryptography policies and procedures covering crosslink authentication; it addresses impersonation by a rogue spacecraft by requiring those measures, while the deployed crosslink authentication, not the policy article, is what defeats spoofed acquisition, time-distribution, and routing messages.

  • nis2Art. 21(2)(j)
    addresses
    moderate
    inferred

    IA-0008.02 succeeds when an impostor (rogue) spacecraft is honored on the inter-satellite link without valid credentials. NIS2 Art. 21(2)(j) governs the risk: correct authentication of the inter-satellite link rejects a peer presenting mission-compatible crosslink traffic but lacking valid keys. Orbital-geometry-aware anomaly detection is a compensating backstop, not the primary obligation.

  • nis2-implAnnex 11.6.1
    mitigates
    high
    derived

    Authentication on crosslink and proximity-domain interfaces converts a rogue spacecraft into an unauthenticated peer; without valid keys it cannot establish a privileged conversation with the target vehicle.

  • nis2-implAnnex 6.8.1
    addresses
    moderate
    derived

    Segmentation between crosslink-facing functions and bus internals is the architectural lever that bounds what a rogue-spacecraft peer can reach even if it briefly occupies the RF geometry.

ENISA controls

  • Communications security on crosslink-compatible signals defeats a rogue spacecraft attempting to advertise services as a trusted neighbor.

  • Bidirectional cryptographic authentication on crosslinks rejects routing/time-distribution messages from an unauthenticated rogue spacecraft.

  • Space-based RF mapping detects an adversary-operated rogue spacecraft from its emissions during phasing and proximity operations.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, IA-0008.02 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.