Space Odyssey: An Experimental Software Security Analysis of Satellites
Johannes Willbold, Moritz Schloegel, Manuel Vögele, Maximilian Gerhardt, Thorsten Holz, Ali Abbasi
Abstract
Satellites are an essential aspect of our modern society and have contributed significantly to the way we live today, most notable through modern telecommunications, global positioning, and Earth observation. In recent years, and especially in the wake of the New Space Era, the number of satellite deployments has seen explosive growth. Despite its critical importance, little academic research has been conducted on satellite security and, in particular, on the security of onboard firmware. This lack likely stems from by now outdated assumptions on achieving security by obscurity, effectively preventing meaningful research on satellite firmware.In this paper, we first provide a taxonomy of threats against satellite firmware. We then conduct an experimental security analysis of three real-world satellite firmware images. We base our analysis on a set of real-world attacker models and find several security-critical vulnerabilities in all analyzed firmware images. The results of our experimental security assessment show that modern in-orbit satellites suffer from different software security vulnerabilities and often a lack of proper access protection mechanisms. They also underline the need to overcome prevailing but obsolete assumptions. To substantiate our observations, we also performed a survey of 19 professional satellite developers to obtain a comprehensive picture of the satellite security landscape.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 18642500-dde1-4344-97ed-b113d0b6e4f2Cited by top-tier papers8
- Orbital Trust and Privacy: SoK on PKI and Location Privacy Challenges in Space NetworksDavid Koisser, Richard Mitev, Nikita Yadav, Franziska Vollmer et al.USENIX Security 2024 · 9 citations
- A Comprehensive Analysis of Security Vulnerabilities and Attacks in Satellite ModemsLingjing Yu, Jingli Hao, Jun Ma, Yong Sun et al.CCS 2024 · 8 citations
- HoneySat: A Network-based Satellite Honeypot FrameworkEfrén López-Morales, Ulysse Planta, Gabriele Marra, Carlos Gonzalez-Cortes et al.NDSS 2026 · 4 citations
- Edge Unlearning is Not "on Edge"! an Adaptive Exact Unlearning System on Resource-Constrained DevicesXiaoyu Xia, Ziqi Wang, Ruoxi Sun, Bowen Liu et al.S&P 2025
- Adversarial Observations in Weather ForecastingErik Imgrund, Thorsten Eisenhofer, Konrad RieckCCS 2025
Builds on5
- ICARUS: Attacking low Earth orbit satellite networksGiacomo Giuliari, Tommaso Ciussani, Adrian Perrig, Ankit SinglaUSENIX ATC 2021 · 99 citations
- A Tale of Sea and Sky On the Security of Maritime VSAT CommunicationsJames Pavur, Daniel Moser, Martin Strohmeier, Vincent Lenders et al.S&P 2020 · 72 citations
- A community-driven approach to democratize access to satellite ground stationsVaibhav Singh, Akarsh Prabhakara, Diana Zhang, Osman Yagan et al.MobiCom 2021 · 32 citations
- QPEP: An Actionable Approach to Secure and Performant Broadband From Geostationary OrbitJames Pavur, Martin Strohmeier, Vincent Lenders, Ivan MartinovicNDSS 2021
- Fuzzware: Using Precise MMIO Modeling for Effective Firmware FuzzingTobias Scharnowski, Nils Bars, Moritz Schloegel, Eric Gustafson et al.USENIX Security 2022
Related papers
- SatBleed: Security of Commoditized Communication Modules in SatellitesUlysse Planta, Julian Rederlechner, Martin Strohmeier, Mathias Fischer et al.S&P 2026
- Space RADSIM: Binary-Agnostic Fault Injection to Evaluate Cosmic Radiation Impact on Exploit Mitigation Techniques in SpaceJohannes Willbold, Tobias Cloosters, Simon Wörner, Felix Buchmann et al.S&P 2025
- Large-scale Security Measurements on the Android Firmware EcosystemQinsheng Hou, Wenrui Diao, Yanhao Wang, Xiaofeng Liu et al.ICSE 2022 · 21 citations
- Unveiling IoT Security in Reality: A Firmware-Centric JourneyNicolas Nino, Ruibo Lu, Wei Zhou, Kyu Hyung Lee et al.USENIX Security 2024 · 12 citations
- A large-scale empirical analysis of the vulnerabilities introduced by third-party components in IoT firmwareBinbin Zhao, Shouling Ji, Jiacheng Xu, Yuan Tian et al.ISSTA 2022 · 49 citations
