USENIX Security2024Top-tier venue
RECORD: A RECeption-Only Region Determination Attack on LEO Satellite Users
Eric Jedermann, Martin Strohmeier, Vincent Lenders, Jens B. Schmitt
Abstract
Low Earth orbit (LEO) satellite communication has recently experienced a dramatic increase of usage in diverse application sectors. Naturally, the aspect of location privacy is becoming crucial, most notably in security or military applications. In this paper, we present a novel passive attack called RECORD, which is solely based on the reception of messages to LEO satellite users on the ground, threatening their location privacy. In particular, we show that by observing only the downlink of 'wandering' communication satellites over wide beams can be exploited at scale from passive attackers situated on Earth to estimate the region in which users are located. We build our own distributed satellite reception platform to implement the RECORD attack. We analyze the accuracy and limiting factors of this new attack using real-world measurements from our own Iridium satellite communication. Our experimental results reveal that by observing only 2.3 hours of traffic, it is possible to narrow down the position of an Iridium user to an area below 11 km of radius (compared to the satellite beam size of 4700 km diameter). We conduct additional extensive simulative evaluations, which suggest that it is feasible to narrow down the unknown location of a user even further, for instance, to below 4 km radius when the observation period is increased to more than 16 hours. We finally discuss the transferability of RECORD to different LEO constellations and highlight possible countermeasures.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 432b1bd8-dac9-48f8-bfa4-b8de19ad63cdCited by top-tier papers3
- Time-varying Bottleneck Links in LEO Satellite Networks: Identification, Exploits, and CountermeasuresYangtao Deng, Qian Wu, Zeqi Lai, Chenwei Gu et al.NDSS 2025
- LPG: Raise Your Location Privacy Game in Direct-to-Cell LEO Satellite NetworksQuan Shi, Liying Wang, Prosanta Gope, Qi Liang et al.USENIX Security 2026
- Starshields for iOS: Navigating the Security Cosmos in Satellite CommunicationJiska Classen, Alexander Heinrich, Fabian Portner, Felix Rohrbach et al.NDSS 2025
Builds on4
- A Tale of Sea and Sky On the Security of Maritime VSAT CommunicationsJames Pavur, Daniel Moser, Martin Strohmeier, Vincent Lenders et al.S&P 2020 · 72 citations
- Evaluating Physical-Layer BLE Location Tracking Attacks on Mobile DevicesHadi Givehchian, Nishant Bhaskar, Eliana Rodriguez Herrera, Héctor Rodrigo López Soto et al.S&P 2022 · 55 citations
- Watch This Space: Securing Satellite Communication through Resilient Transmitter FingerprintingJoshua Smailes, Sebastian Köhler, Simon Birnbach, Martin Strohmeier et al.CCS 2023 · 25 citations
- LTrack: Stealthy Tracking of Mobile Phones in LTEMartin Kotuliak, Simon Erni, Patrick Leu, Marc Röschlin et al.USENIX Security 2022
Related papers
- Mind the Location Leakage in LEO Direct-to-Cell Satellite NetworksWeisen Liu, Zeqi Lai, Qian Wu, Hewu Li et al.S&P 2025
- LEO-Range: Physical Layer Design for Secure Ranging with Low Earth Orbiting SatellitesDaniele Coppola, Arslan Mumtaz, Giovanni Camurati, Harshad Sathaye et al.USENIX Security 2025
- GNSS-WASP: GNSS Wide Area SPoofingChristopher Tibaldo, Harshad Sathaye, Giovanni Camurati, Srdjan CapkunUSENIX Security 2025
- Practical Attacks Against Privacy and Availability in 4G/LTE Mobile Communication SystemsAltaf Shaik, Jean-Pierre Seifert, Ravishankar Borgaonkar, N. Asokan et al.NDSS 2016 · 342 citations
- Surveilling the Masses with Wi-Fi-Based Positioning SystemsErik C. Rye, Dave LevinS&P 2024 · 5 citations
