Space Odyssey: An Experimental Software Security Analysis of Satellites
Johannes Willbold, Moritz Schloegel, Manuel Vögele, Maximilian Gerhardt, Thorsten Holz, Ali Abbasi
摘要
Satellites are an essential aspect of our modern society and have contributed significantly to the way we live today, most notable through modern telecommunications, global positioning, and Earth observation. In recent years, and especially in the wake of the New Space Era, the number of satellite deployments has seen explosive growth. Despite its critical importance, little academic research has been conducted on satellite security and, in particular, on the security of onboard firmware. This lack likely stems from by now outdated assumptions on achieving security by obscurity, effectively preventing meaningful research on satellite firmware.In this paper, we first provide a taxonomy of threats against satellite firmware. We then conduct an experimental security analysis of three real-world satellite firmware images. We base our analysis on a set of real-world attacker models and find several security-critical vulnerabilities in all analyzed firmware images. The results of our experimental security assessment show that modern in-orbit satellites suffer from different software security vulnerabilities and often a lack of proper access protection mechanisms. They also underline the need to overcome prevailing but obsolete assumptions. To substantiate our observations, we also performed a survey of 19 professional satellite developers to obtain a comprehensive picture of the satellite security landscape.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper8
- Orbital Trust and Privacy: SoK on PKI and Location Privacy Challenges in Space NetworksDavid Koisser, Richard Mitev, Nikita Yadav, Franziska Vollmer 等USENIX Security 2024 · 被引用 9 次
- A Comprehensive Analysis of Security Vulnerabilities and Attacks in Satellite ModemsLingjing Yu, Jingli Hao, Jun Ma, Yong Sun 等CCS 2024 · 被引用 8 次
- HoneySat: A Network-based Satellite Honeypot FrameworkEfrén López-Morales, Ulysse Planta, Gabriele Marra, Carlos Gonzalez-Cortes 等NDSS 2026 · 被引用 4 次
- Edge Unlearning is Not "on Edge"! an Adaptive Exact Unlearning System on Resource-Constrained DevicesXiaoyu Xia, Ziqi Wang, Ruoxi Sun, Bowen Liu 等S&P 2025
- Adversarial Observations in Weather ForecastingErik Imgrund, Thorsten Eisenhofer, Konrad RieckCCS 2025
它引用的顶会 Paper5
- ICARUS: Attacking low Earth orbit satellite networksGiacomo Giuliari, Tommaso Ciussani, Adrian Perrig, Ankit SinglaUSENIX ATC 2021 · 被引用 99 次
- A Tale of Sea and Sky On the Security of Maritime VSAT CommunicationsJames Pavur, Daniel Moser, Martin Strohmeier, Vincent Lenders 等S&P 2020 · 被引用 72 次
- A community-driven approach to democratize access to satellite ground stationsVaibhav Singh, Akarsh Prabhakara, Diana Zhang, Osman Yagan 等MobiCom 2021 · 被引用 32 次
- QPEP: An Actionable Approach to Secure and Performant Broadband From Geostationary OrbitJames Pavur, Martin Strohmeier, Vincent Lenders, Ivan MartinovicNDSS 2021
- Fuzzware: Using Precise MMIO Modeling for Effective Firmware FuzzingTobias Scharnowski, Nils Bars, Moritz Schloegel, Eric Gustafson 等USENIX Security 2022
相关 Paper
- SatBleed: Security of Commoditized Communication Modules in SatellitesUlysse Planta, Julian Rederlechner, Martin Strohmeier, Mathias Fischer 等S&P 2026
- Space RADSIM: Binary-Agnostic Fault Injection to Evaluate Cosmic Radiation Impact on Exploit Mitigation Techniques in SpaceJohannes Willbold, Tobias Cloosters, Simon Wörner, Felix Buchmann 等S&P 2025
- Large-scale Security Measurements on the Android Firmware EcosystemQinsheng Hou, Wenrui Diao, Yanhao Wang, Xiaofeng Liu 等ICSE 2022 · 被引用 21 次
- Unveiling IoT Security in Reality: A Firmware-Centric JourneyNicolas Nino, Ruibo Lu, Wei Zhou, Kyu Hyung Lee 等USENIX Security 2024 · 被引用 12 次
- A large-scale empirical analysis of the vulnerabilities introduced by third-party components in IoT firmwareBinbin Zhao, Shouling Ji, Jiacheng Xu, Yuan Tian 等ISSTA 2022 · 被引用 49 次
