Small Satellites, Large Supply-Chain Attack Surfaces
Small satellites increasingly rely on commercial off-the-shelf components. That approach makes it possible to assemble systems from existing hardware and software, but it also creates dependencies on components supplied by many different parties.
Our paper, SpyChain: Multi-Vector Supply Chain Attacks on Small Satellite Systems, examines how those dependencies expand the attack surface beyond the satellite’s flight software.
Looking across the supply chain
A security assessment focused only on the main software can miss threats introduced through auxiliary hardware or supporting software. SpyChain studies supply-chain threats involving both independently malicious components and components that collude.
That distinction matters because the behavior of one component may look different when it interacts with another compromised part of the system. Examining each component in isolation can leave questions about the combined system unanswered.
Studying attacks in a simulation framework
The research uses NASA’s NOS3 simulation framework to investigate these threats. It shows how malicious components can evade testing, exfiltrate telemetry, disrupt operations, and coordinate through covert channels.
The work therefore considers several consequences of a compromised supply chain. Data confidentiality is one concern, but the behavior and availability of the system are also part of the security picture.
From individual components to coordinated behavior
A supply-chain attack may involve a single component or span several parts of the system. Coordinated attacks make it especially important to consider interactions, rather than assessing trust only at the boundary of each component.
SpyChain’s investigation is conducted with a simulation framework. Its findings should be understood in that setting rather than as a report of attacks observed against satellites in orbit.
Lightweight defenses
The paper introduces lightweight onboard defenses, including runtime monitoring, to mitigate the threats studied. Runtime monitoring complements testing by examining behavior while the system operates, when interactions among components may reveal problems that earlier checks missed.
The broader takeaway is that satellite security depends on the components around flight software as well as the flight software itself. Supply-chain assessment and defenses need to account for those relationships.