{"id":4058,"date":"2024-06-17T07:00:00","date_gmt":"2024-06-17T12:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/cyber-risk\/space-final-frontier-cyberattacks"},"modified":"2024-06-17T07:00:00","modified_gmt":"2024-06-17T12:00:00","slug":"space-the-final-frontier-for-cyberattacks","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/06\/17\/space-the-final-frontier-for-cyberattacks\/","title":{"rendered":"Space: The Final Frontier for Cyberattacks"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt75098e5137c01a6d\/666c8c9df826a38f043598fb\/outerspace_Gorodenkoff_shutterstock.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/space-the-final-frontier-for-cyberattacks.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/space-the-final-frontier-for-cyberattacks.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A distributed denial-of-service (DDoS) attack this week disabled electronic door locks across a major lunar settlement, trapping dozens of people indoors and locking out many more in lethal cold. The threat actor behind the attack is believed responsible for also commandeering a swarm of decades-old CubeSats last year and attempting to use them to trigger a chain reaction of potentially devastating satellite crashes.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Neither &#8220;incident&#8221; has happened, of course. Yet. But they well could, sometime in the not-too-distant future, and now is the time to start thinking about and planning for them.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">That&#8217;s the takeaway from a new US National Science Foundation (NSF)-funded study on <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/spacecybersecurity.org\/\" rel=\"noopener\">Outer Space Cyberattacks<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> by researchers at the California Polytechnic State University (Cal Poly). The 95-page report examines a confluence of potential drivers for a new frontier in cyberattacks over the next several decades as countries \u2014 and private industry \u2014 jostle for dominance and influence in outer space.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"A Taxonomy for Space Cybersecurity\">A Taxonomy for Space Cybersecurity<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The report first and foremost offers a taxonomy for space cybersecurity that researchers can use to spin up virtually millions of novel cyber-enabled attack scenarios involving launch and ground infrastructure, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/ics-ot-security\/moonlighter-satellite-in-orbit-target-space-hackers\" rel=\"noopener\">satellites<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, space stations, satellite phones and terminals, and communications links from ground to space.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The theoretical lunar door lock attack and CubeSat swarm hijack are two among 42 scenarios that the authors provide as a sampling of how researchers can use the taxonomy to conjure up all the different ways in which cyberattacks could unfold in space. Other examples include injecting fake data related to extraterrestrial life in a deep space mission to trigger an unmerited, costly, and time consuming response; or contaminating critical food supplies to an outer space encampment by attacking systems controlling those supplies.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The taxonomy itself is presented in the form of a matrix called ICARUS (which stands for &#8220;Imagining Cyberattacks to Anticipate Risks Unique to Space&#8221;). The matrix lists all the major variables that constitute a cyberattack and organize them by attack vector, type of exploits, potential threat actor motivations, victims, and the various space capabilities that an attack could compromise. By selecting a variable from two or more of these categories, researchers can create more than 4 million novel scenarios for cyberattacks in outer space, according to the researchers.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;There are several reasons to think that <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/cybersecurity-best-practice-is-critical-for-winning-the-new-space-race\" rel=\"noopener\">cyberattacks will be the dominant form of conflict in space<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">,&#8221; says Patrick Lin, lead author of the report and director of Cal Poly&#8217;s Ethics + Emerging Sciences Group.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Yet, most discussions \u2014 the unclassified ones at least \u2014 that involve cyber threats in space rarely tend to go beyond some generic <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-analytics\/how-researchers-hijacked-a-satellite\" rel=\"noopener\">scenarios of satellite hacking<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> or jamming, signal spoofing, or disabling GPS communications, Lin says. &nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Partly, that&#8217;s because all reported incidents of cyberattacks against space targets so far have only involved one of these components. The most recent example is Russia&#8217;s February 2022 attack on US communications company <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/aerospaceamerica.aiaa.org\/features\/why-the-viasat-hack-still-echoes\/\" rel=\"noopener\">Viasat<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> that disrupted satellite connectivity to tens of thousands of customers across Europe. The other is an increasingly dangerous failure to consider or acknowledge all the different attack surfaces that are opening up as government and private sector organizations rush to deploy myriad new technologies in space \u2014 from giant spaceships to tiny CubeSats for scientific research.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"A Failure to Imagine Space Attacks\">A Failure to Imagine Space Attacks<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Since failing to imagine a full range of threats can be disastrous for any security planning, we need more than the usual scenarios that are typically considered in space-cybersecurity discussions,&#8221; Lin says. &#8220;Our ICARUS matrix fills that &#8216;imagineering&#8217; gap.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Lin and the other authors of the report \u2014 Keith Abney, Bruce DeBruhl, Kira Abercromby, Henry Danielson, and Ryan Jenkins \u2014 identified several factors as increasing the potential for outer space-related cyberattacks over the next several years and decades.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Among them is the rapid congestion of outer space in recent years as the result of nations and private companies racing to deploy space technologies; the remoteness of space; and technological complexity.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As the report notes, the number of registered objects in space \u2014 most of which are satellites \ufffd\ufffd\u2014 have been climbing at an astonishing pace recently after holding steady at around 150 new objects per year between 1965 and 2012. In the last two years that number stood at 2,600 new objects on average each year.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The remoteness \u2014 and vastness of space \u2014 also makes it more challenging for stakeholders \u2014 both government and private \u2014 to address vulnerabilities in space technologies. There are numerous objects that were deployed into space long before cybersecurity became a mainstream concern that could become targets for attacks.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;And, as crazy as it sounds, satellites are still being launched today with no cybersecurity, such as CubeSats that are popular with university labs and others for their inexpensive cost to build and launch,&#8221; the report noted. &#8220;They typically have neither the onboard room to squeeze in cybersecurity components nor the budget for it anyway.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Space Junk, Technological Complexity &amp; More\">Space Junk, Technological Complexity &amp; More<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Exacerbating the situation is the growing complexity of space systems \u2014 which are often still prototypes at deployment \u2014 and the relative lack of attempts to understand or study cyber-exploitable vulnerabilities in them. There&#8217;s a general lack of public information around potential cyber issues in space technologies as well \u2014 and space supply chain in general \u2014 sometimes because of technological novelty, or because of security classification reasons or because of a manufacturer&#8217;s unwillingness to disclose details.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Interestingly, the self-interest among stakeholders to avoid contributing to the growing problem of space debris could ironically force adversaries to avoid kinetic conflict in outer space and use cyber means as a way to settle scores. There are currently some 35,000 pieces of trackable space junk and more than 1 million smaller bits \u2014 and no one really wants to increase that volume by crashing or blowing up other space objects, the report noted.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Lin and his colleagues also identified unclear legal regimes and the potentially high visibility and impact of cyberattacks on space assets as also potentially driving adversary interest in future.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Assessing capabilities in cybersecurity is never easy, and it\u2019s even worse for the space domain because of the inherent national-security concerns that may classify much of that information,&#8221; Lin says. &#8220;Space cybersecurity is shrouded in mystery from the start, which isn&#8217;t surprising since space launches started as military missions.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">But security by obscurity will not be an option for long, he says. Already researchers have <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/ics-ot-security\/european-space-agency-explores-cybersecurity-space-industry\" rel=\"noopener\">begun looking for vulnerabilities in space technologies<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> he says pointing to several teams that successfully <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/hackasat.com\/\" rel=\"noopener\">hacked a 3U CubeSat<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> at DEFCON last year &#8220;Cybersecurity is benefitted when more researchers can focus on a problem, but the classification of technical details and the lack of general awareness about space cybersecurity are preventing more cybersecurity practitioners from engaging with the problem here.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Lin says there are several key audiences for the report with <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cloud-security\/us-space-force-wants-700m-cybersecurity\" rel=\"noopener\">space cybersecurity professionals \u2014 both technical and policy-related<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> \u2014 being the prime ones: &#8220;Even if they understand the drivers of the problem \u2014 and it&#8217;s critical to understand a problem in order to solve it \u2014 security planners can always use help in anticipating novel threats.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Second, the report also seeks to raise awareness of the problem with researchers from other disciplines, especially non-technical ones like the social sciences and humanities, Lin says. And third, &#8220;we also want to raise awareness with the broader public because&nbsp;we&#8217;re all stakeholders&nbsp;here by virtue of being possible victims,&#8221; he adds.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyber-risk\/space-final-frontier-cyberattacks\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A distributed denial-of-service (DDoS) attack this week disabled electronic door<\/p>\n","protected":false},"author":12,"featured_media":4059,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-4058","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/space-the-final-frontier-for-cyberattacks.jpg?fit=1000%2C563&ssl=1",1000,563,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/space-the-final-frontier-for-cyberattacks.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/space-the-final-frontier-for-cyberattacks.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/space-the-final-frontier-for-cyberattacks.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/space-the-final-frontier-for-cyberattacks.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/space-the-final-frontier-for-cyberattacks.jpg?fit=1000%2C563&ssl=1",1000,563,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/space-the-final-frontier-for-cyberattacks.jpg?fit=1000%2C563&ssl=1",1000,563,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/space-the-final-frontier-for-cyberattacks.jpg?fit=1000%2C563&ssl=1",1000,563,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/space-the-final-frontier-for-cyberattacks.jpg?resize=825%2C563&ssl=1",825,563,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/space-the-final-frontier-for-cyberattacks.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/space-the-final-frontier-for-cyberattacks.jpg?fit=1000%2C563&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4058","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=4058"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4058\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/4059"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=4058"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=4058"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=4058"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}