Developing Scenarios Supporting Space-based IDS
John Thebarge, Wayne C. Henry, Gregory J. Falco · ASCEND 2022 · 2022
View Video Presentation: https://doi.org/10.2514/6.2022-4219.vid Satellites are essential to critical and commercial infrastructure used by governments, militaries, and industries worldwide. Satellites are prime targets for malicious cyber actors thanks to their relatively minimal defenses, the significance of their compromise, and their low barrier to entry. Due to technical limitations, satellite operators are hindered in their ability to quickly detect and respond to the presence of a cyber threat. Intrusion detection systems have demonstrated value in critical infrastructure, allowing operators to detect and prevent cyberattacks on their systems. The lack of cybersecurity resources that provide insight into adversarial attack patterns challenges the development of an intrusion detection system onboard a satellite. To overcome the lack of cybersecurity resources, we approach intrusion detection systems for satellites through the lens of penetration testing. This work begins by following the penetration testing process on a notional cube satellite to generate attack scenarios that can disrupt the satellite’s operations. We then compare the satellite attack scenarios with similar terrestrial-based attack patterns found in the MITRE ATT&CK framework and the common attack pattern enumeration and classification catalog. Through this comparison, satellite components that require malicious activity monitoring are identified and used as a medium for discussing a host-based and network-based intrusion detection system onboard a satellite. This paper concludes with the limitations of intrusion detection systems in a space-based environment.