Source-linked AI summary

Temporal Risk on Satellites

Shiqi Liu, Kun Sun

arXiv:2608.20575v1cs.CR

TL;DR

Satellite cybersecurity risk is difficult to assess with static frameworks because attack feasibility and consequences depend on physical time, mission schedules, orbital conditions, and environmental state. The paper introduces a temporal framework that extends existing risk matrices with temporal adversary capabilities and time-dependent exploitation difficulty. It produces time-indexed likelihood-impact assessments, with eclipse identified as a higher-risk period than sunlight in the example analysis.

  • Problem

    Existing satellite cybersecurity risk frameworks largely treat risk as time-invariant despite attack feasibility and impact varying with mission timing and space-environment conditions.

  • Method

    The framework extends SPARTA with a five-dimensional temporal mastery profile and separates static exploitation difficulty from Temporal Exploitation Difficulty across mission windows and environmental bands.

  • Results

    Eclipse carries the highest risk in the example analysis, with stricter controls supported during eclipse and less restrictive non-critical throttling during sunlight.

  • Takeaways & Limitations

    Time-indexed likelihood-impact matrices give operators a time-aware view for relating risk to orbital dynamics, mission timelines, and space weather.

  • Takeaways & Limitations

    The framework remains semi-quantitative because temporal likelihood and impact levels are elicited from experts, while incident data and standardized validation benchmarks remain scarce.

Abstract

from arXiv · show

Satellite vulnerabilities change over time as orbits shift, power margins tighten, and the space environment deteriorates. However, most cybersecurity risk frameworks still treat threats as static. In practice, the same exploit can be far more damaging during a critical maneuver than during routine operations. We propose a temporal risk assessment framework that makes time an explicit axis in satellite security analysis. It extends existing adversary behavior taxonomies with a five-dimensional temporal capability model and estimates exploitation difficulty across distinct temporal windows of a mission. Rather than producing a single risk score, the framework outputs a series of time-indexed likelihood-impact matrices. It discretizes missions into operationally meaningful time windows and environmental bands to show when systems are most exposed. This view helps operators avoid scheduling sensitive operations in high-risk periods and align defensive resources with a threat landscape that shifts over time.

I. INTRODUCTION

Satellite systems are critical, increasingly exposed infrastructure whose security risks depend on mission timing and environmental conditions. The paper addresses static risk frameworks by introducing a temporal assessment framework for satellite cybersecurity.

  • Motivation: Satellite systems support communications, navigation, and Earth observation, while interconnected architectures, COTS hardware, and inexpensive ground services expand their attack surface.The 2022 KA-SAT cyberattack illustrates that satellite security threats have produced real communication disruptions.
  • Motivation: Orbital mechanics, mission-critical operations, radiation effects, and power-state changes make attack feasibility and impact vary across operational time windows.Examples include maneuvers, payload activations, downlinks, South Atlantic Anomaly passages, geomagnetic storms, and eclipse periods.
  • Research gap: Existing frameworks treat risk as essentially time-invariant, leaving likelihood estimation incomplete because they do not model adversaries’ temporal capabilities or changing attack difficulty.The supplied passage identifies static risk treatment as a central gap in current approaches.
  • Contribution: The proposed framework extends SPARTA’s 5×5 likelihood-impact matrix into time-indexed matrices for mission windows and environmental bands.It defines temporal risk in terms of physical time, orbital mechanics, and mission schedules rather than CVSS vulnerability lifecycle metrics.

II. BACKGROUND & RELATED WORK

Prior work shows that satellite attack surfaces span ground, link, user, and space segments, with vulnerabilities and access paths distributed across the mission architecture. This motivates end-to-end security analysis rather than spacecraft-only assessment.

  • Attack surface: Satellite attack surfaces span ground, link, user, and space segments, and compromises in ground infrastructure can cascade to space assets.Ground networks, GSaaS platforms, and operational tooling are identified as foothold opportunities.
  • Attack surface: Jamming and spoofing remain prominent threats in link and user segments, while modem and terminal layers contain documented design and implementation defects.Teardown and measurement studies provide concrete exploitation paths for LEO terminals and user equipment.
  • Ground segment: Lower ground-station costs and GSaaS have reduced physical and economic barriers to interacting with orbital assets and triggering software vulnerabilities.In-orbit firmware analyses also report weak telecommand protection, missing access control, and multiple software defects.
  • Resilience: Isolation, recovery, independent health monitoring, and out-of-band telemetry are emerging resilience measures for satellites running complex operating-system stacks.Application sandboxes are being evaluated as a practical isolation layer for CubeSat-class missions, alongside independent monitoring and telemetry proposals.

B. MITRE ATT&CK in Space

MITRE ATT&CK provides a common matrix-based vocabulary for adversary behavior, while SPARTA adapts that structure to space cyber operations. SPARTA assigns techniques to a 5×5 likelihood-impact risk matrix.

  • Risk matrix: Figure 1 presents the risk-matrix representation used by the SPARTA-related framework.The supplied caption identifies the figure as a risk matrix representation.
  • MITRE ATT&CK: MITRE ATT&CK is a matrix-based knowledge base that provides a common lexicon of adversary tactics, techniques, and procedures.It supports adversary emulation and detection coverage assessment across multiple domains.
  • SPARTA: SPARTA defines a space cyber tactics-and-techniques matrix and assigns each technique a Notional Risk Score in a 5×5 likelihood-impact matrix.Likelihood incorporates adversary motivation, exploitation difficulty, and capability tier, while impact covers mission and broader consequences.

III. METHODOLOGY

The methodology converts static risk assessment into a time-resolved analysis by scoring likelihood and impact across relevant mission windows. It adjusts likelihood using time-dependent exploitation difficulty and adversary capabilities while preserving the existing motivation and impact categories.

  • Temporal scoring: For each technique, the framework examines how likelihood and impact vary across relevant time windows and assigns 1–5 levels to each window.This extends the static matrix without replacing its discrete scoring structure.
  • Likelihood assessment: Likelihood assessment applies time-dependent adjustments to Exploitation Difficulty and Adversary Capabilities, while Motivation retains its original meaning.Temporal accessibility and adversary timing proficiency change the assessment, but target attractiveness remains primarily tied to system criticality.
  • Impact assessment: Time modulates realized impact and determines which unchanged I1–I5 consequence level a specific attack scenario maps to.The impact category scheme and its semantics remain unchanged even though operational windows affect consequence severity.

A. Temporal Adversary Capabilities

The framework preserves seven attacker tiers while embedding temporal proficiency through a five-dimensional mastery profile and tier-specific minimum capability sets.

  • Temporal mastery profile: The temporal mastery profile comprises actuation, forecasting, sensing, synchronization, and hiding.These dimensions capture timing-related abilities such as acting within access windows, predicting time-localized opportunities, sensing connectivity, coordinating actions, and concealing behavior.
  • Attacker tiers: The framework retains the seven-tier attacker categorization used by existing space cybersecurity frameworks.Temporal capabilities are mapped into attacker capability metrics rather than replacing the original tiers.
  • Temporal capability sets: Each attacker tier is assigned a minimum required set of temporal capabilities.These sets determine which attacker classes can satisfy the timing requirements of different adversarial operations.
  • Capability dimensions: Actuation is bounded by practical access constraints including line-of-sight, antenna pointing, and radio-frequency chain availability.The exploitable window is therefore constrained by the visibility window and engineering conditions.

B. Temporal Exploitation Difficulty

Temporal Exploitation Difficulty measures the challenge of executing a known technique at the right time, using window properties and scenario-specific constraints to produce time-indexed risk assessments.

  • Definition: Temporal Exploitation Difficulty is orthogonal to static exploitation difficulty and measures the difficulty of exploiting a technique at the right time.Static difficulty covers code complexity, tooling, and non-temporal preconditions, while TED assumes the attacker already knows how to execute the technique in principle.
  • Intrinsic properties: TED incorporates intrinsic window properties such as duration, recurrence, predictability, and whether opportunities are one-shot or repeatable.Routine downlink passes offer frequent, predictable windows with slack, whereas geomagnetic-storm or contingency windows are less predictable in practice.
  • Likelihood assessment: Likelihood combines motivation, static exploitation difficulty, TED, and minimum attacker tier through semi-quantitative expert elicitation.The elicitation explicitly accounts for temporal considerations rather than using a closed-form expression.
  • Risk representation: Likelihood and impact are modeled as functions of time, L(t) and I(t), then projected onto discrete 1–5 likelihood-impact matrices.The approach avoids a full three-dimensional risk surface while retaining time variation through matrix snapshots.
  • Time discretization: The framework discretizes missions into operationally meaningful windows, including passes, mission phases, eclipse intervals, and environmental bands.This keeps the number of risk-matrix snapshots tractable while preserving time-resolved and environment-aware analysis.

IV. CASE STUDY

The STARMELT case study applies the temporal framework to a battery-depleting valid-command technique whose risk differs between sunlight and eclipse in LEO operations.

  • Case-study technique: STARMELT maps under SPARTA to EX-0013.01: Valid Commands, involving protocol-valid actions that progressively deplete stored battery energy.The case study treats the attack as a technique that exploits legitimate command behavior to drain onboard resources.
  • Static assessment: SPARTA assigns STARMELT a static NRS of 25 (High) for high-criticality satellite systems using worst-case Likelihood and Impact.This single score does not distinguish the satellite’s power regime across the orbit.
  • Temporal contrast: Sunlight and eclipse produce different consequences because the platform is typically power-positive in sunlight but operates on battery discharge during eclipse.The case study uses this power-regime difference to motivate time-resolved assessment of the same technique.

A. Likelihood Analysis

The STARMELT likelihood analysis identifies the temporal capabilities and operational constraints needed for the attack, finding higher exploitation difficulty during eclipse than sunlight.

  • Required capabilities: STARMELT requires at least Tier-4 temporal capabilities because its execution depends on coordinated timing, sensing, forecasting, and traffic actuation.The assumed capability set is derived from the attack’s timing and communication requirements.
  • Required capabilities: The minimal temporal capability set for STARMELT is MT = {A, F, S, Y }.A denotes actuation, F forecasting, S sensing, and Y synchronization for the attack scenario.
  • Temporal difficulty: Eclipse moderately increases TED because its shorter window reduces temporal slack, retries, and margin for timing error.The attack can begin on demand but must reach and maintain a sufficient injection rate within the available window.
  • Scenario constraints: Ground-to-satellite saturation is geometry-limited, while inter-satellite-link saturation is topology-limited as connectivity evolves.Illumination-driven operational behavior can further shrink the effective usable portion of each window and is treated as a scenario-specific constraint.

B. Impact Analysis

Operational impact depends strongly on the satellite’s power state. Eclipse conditions can turn sustained traffic into battery wear and potentially disrupt spacecraft operations.

  • Sunlight limits STARMELT’s energy impact because solar arrays cover bus load and recharge the battery.The evaluated illuminated case showed no increase in battery depth-of-discharge, leaving primarily non-energy effects.
  • Eclipse forces reliance on battery discharge, so keeping the satellite awake accelerates battery wear and reduces effective battery life.The evaluated setting reported up to ∼76% reduction over 1.5 years across repeated eclipse intervals.
  • Eclipse-induced power loss may trigger undervoltage protection and safe modes, with worst-case effects on attitude control and communications.

C. Operational Value

The temporal comparison shows a clear operational split: eclipse carries the highest risk, while sunlight is materially lower. This supports tighter eclipse controls while preserving throughput during sunlight without dropping baseline safeguards.

  • Eclipse carries the highest risk, whereas sunlight is materially lower in the temporal comparison.
  • Operators can apply stricter controls during eclipse and less restrictive non-critical throttling during sunlight to preserve throughput.Baseline safeguards should remain in place in both conditions.

V. DISCUSSION

The framework links risk to operational windows and environmental bands, but its calibration, strategic modeling, and constellation-wide scalability remain open challenges. Future work must validate temporal profiles and aggregate them without losing essential timing structure.

  • Temporal risk models remain semi-quantitative because likelihood and impact are still elicited from experts.Public incident data are scarce and incomplete, and standardized time-aware exercises, simulations, and benchmarks are lacking.
  • The framework does not yet model attackers and defenders strategically choosing when to act.Future attack-defense games could represent attackers selecting exploit windows and defenders choosing when to harden, monitor, or reschedule operations.
  • The current temporal abstractions target a single spacecraft and environment, limiting direct scalability to constellations and shared infrastructure.Enumerating combinations of windows, environmental bands, assets, and services does not scale, motivating orbital-plane-level aggregation that preserves temporal structure.
  • Temporal diversity could support risk-aware routing by directing traffic away from satellites entering staggered high-risk windows.The passage identifies staggered South Atlantic Anomaly transits across orbital planes as an example.
  • The framework represents risk through likelihood-impact matrices parameterized by operational windows and environmental bands.This connects assessment to orbital dynamics, mission timelines, and space weather while complementing existing frameworks.
Loading 2608.20575v1…