SatBleed: Security of Commoditized Communication Modules in Satellites

📅 2026-05-18
🏛️ IEEE Symposium on Security and Privacy
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study presents the first systematic security assessment of commercial off-the-shelf (COTS) communication modules for small satellites, addressing critical vulnerabilities arising from inherent architectural flaws. By establishing a comprehensive threat taxonomy, we integrate threat modeling, static and dynamic code analysis, reverse engineering, and open-source telemetry data correlation to deeply investigate firmware, protocol, and architectural weaknesses in mainstream modules. Our analysis reveals multiple overlooked attack surfaces and uncovers several classes of severe vulnerabilities. Notably, we infer that at least 28 on-orbit missions are exposed to potential hostile takeover risks. These findings provide crucial empirical evidence for advancing spacecraft cybersecurity defenses.
📝 Abstract
Substantial reduction in launch and manufacturing costs has resulted in the accelerated deployment of small satellite missions, with commercial off-the-shelf (COTS) components becoming the prevailing standard for specific subsystems. However, this modular architecture introduces critical security risks, most notably in the Communication Subsystem (COM), which is continuously exposed by design and implicitly trusted as the entry point for command and control. We construct a tailored threat taxonomy for attacks targeting the COM subsystem and analyze representative COM systems from various vendors. Our findings uncover severe vulnerabilities across firmware, protocols, and architectural designs. This work presents the first in-depth security evaluation of widely deployed COTS COM modules employed in small satellites, identifying vulnerabilities affecting dozens of missions. To assess the real-world impact, we correlate our discoveries with open-source telemetry data, inferring at least 28 vulnerable missions in orbit that are susceptible to hostile takeover. Our work reveals that satellite COM subsystems form an attractive and dangerously neglected attack surface, necessitating urgent attention from the community.
Problem

Research questions and friction points this paper is trying to address.

Satellite Security
Commercial Off-The-Shelf (COTS)
Communication Subsystem
Vulnerability Assessment
Threat Taxonomy
Innovation

Methods, ideas, or system contributions that make the work stand out.

Satellite Security
Commercial Off-The-Shelf (COTS)
Communication Subsystem
Threat Taxonomy
Vulnerability Analysis
🔎 Similar Papers
No similar papers found.