• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to secondary sidebar
  • Skip to footer
  • NEWS:
  • SatNews
  • SatMagazine
  • MilSatMagazine
  • SmallSat News
  • |     EVENTS:
  • SmallSat Symposium
  • Satellite Innovation
  • MilSat Symposium
  • SmallSat Europe

SatNews

Satellite Industry Intelligence Since 1983

Subscribe
  • LATEST
  • SatNews Events
  • Magazines
  • Calendar
  • Subscribe
  • Missions & Constellations
    • Exploration & Science Missions
    • In-Orbit Servicing & Orbital Operations
    • LEO Constellations
    • Mission Autonomy & Onboard Systems
    • Mission Deployments & Manifests
    • Navigation & PNT
    • SmallSat
    • Spacecraft & Payload Technology
    View All in Missions & Constellations →
    SpaceX’s Secret ‘Starfall’ Capsule Wins FAA Approval for Pacific Reentry TestsSpaceX’s Secret ‘Starfall’ Capsule Wins FAA Approval for Pacific Reentry Tests
    NOAA Activates First Dedicated U.S. Space Weather Satellite One Million Miles from EarthNOAA Activates First Dedicated U.S. Space Weather Satellite One Million Miles from Earth
    Thales Alenia Space to coordinate EROSS SC On-Orbit Servicing projectThales Alenia Space to coordinate EROSS SC On-Orbit Servicing project
    Astroscale Launches Industry Initiative to Study Atmospheric Impact of Spacecraft ReentryAstroscale Launches Industry Initiative to Study Atmospheric Impact of Spacecraft Reentry
  • Business
    • Contracts & Commercial Deals
    • Earnings & Financial Reporting
    • Events & Conferences
    • Funding & Venture Capital
    • Market Forecasts
    • Mergers & Acquisitions
    • Personnel Moves & Appointments
    View All in Business & Finance →
    SOMA Satellite Factory: Planet Labs Expands San Francisco HQ to Supercharge Production PipelineSOMA Satellite Factory: Planet Labs Expands San Francisco HQ to Supercharge Production Pipeline
    Riding the Starship: The SpaceX IPO Is Set to Rocket Seattle’s Aerospace EcosystemRiding the Starship: The SpaceX IPO Is Set to Rocket Seattle’s Aerospace Ecosystem
    Space Race Moves to Wall Street: China’s Private Rocket Makers Target IPOs as Historic SpaceX Flotation NearsSpace Race Moves to Wall Street: China’s Private Rocket Makers Target IPOs as Historic SpaceX Flotation Nears
    Behind the Screens: The Massive Video Over-IP Infrastructure Powering the World CupBehind the Screens: The Massive Video Over-IP Infrastructure Powering the World Cup
  • Defense
    • Counterspace & ASAT
    • Defense Budgets & Procurement
    • ISR & Reconnaissance
    • MILSATCOM
    • Missile Warning & Defense
    • National Security Programs
    • Space Domain Awareness
    View All in Military & Defense →
    Space-Based Shield: Spire Global and Diehl Defence Partner to Build European Missile Warning NetworkSpace-Based Shield: Spire Global and Diehl Defence Partner to Build European Missile Warning Network
    Qorvo Unveils Compact X-Band Radar Module to Enhance Defense System PerformanceQorvo Unveils Compact X-Band Radar Module to Enhance Defense System Performance
    Energration and Atombeam Partner on DARPA Proposal to Revolutionize Tactical Data Movement at the Defense EdgeEnergration and Atombeam Partner on DARPA Proposal to Revolutionize Tactical Data Movement at the Defense Edge
    American military space closed around one company in seven daysAmerican military space closed around one company in seven days
  • Gov
    • Export Controls & Compliance
    • International Space Agreements
    • National Space Policy
    • Space Law & Treaties
    • Space Sustainability & Debris Policy
    • Space Traffic Management / Debris Removal
    View All in Government & Regulation →
    Major opportunities for 2 GHz over EuropeMajor opportunities for 2 GHz over Europe
    “Dual-use” is the funding word. It’s also the label operators want off.“Dual-use” is the funding word. It’s also the label operators want off.
    Sovereignty got an answer on Day 3. Two answers, actually, and a commercial veto.Sovereignty got an answer on Day 3. Two answers, actually, and a commercial veto.
    Dependency killed the old debate. Sovereignty is the new one, and Europe hasn’t agreed what it means.Dependency killed the old debate. Sovereignty is the new one, and Europe hasn’t agreed what it means.
  • Launch
    • Launch Providers
    • Launch Schedule & Calendars
    • Launch Sites & Infrastructure
    • Rocket Technology & Vehicles
    View All in Launch →
    Breaking the TRL Bottleneck: Space Phoenix Systems Debuts Cost-Effective Space Test-and-Return ServiceBreaking the TRL Bottleneck: Space Phoenix Systems Debuts Cost-Effective Space Test-and-Return Service
    Twelve Scientific Payloads Experience Microgravity Aboard SubOrbital Express-5Twelve Scientific Payloads Experience Microgravity Aboard SubOrbital Express-5
    Amazon Leo Constellation Surpasses 330 Satellites Following Latest Atlas V LaunchAmazon Leo Constellation Surpasses 330 Satellites Following Latest Atlas V Launch
    If You Thought Space Was Hard Try to Get Your Satellite On a RocketIf You Thought Space Was Hard Try to Get Your Satellite On a Rocket
  • Software
    • Autonomous Ground Operations
    • Data Processing & AI/ML
    • Digital Twins & Modeling
    • Ground Segment & Teleports
    • Mission Planning & Simulation
    • Space Systems Software Engineering
    • Spectrum & Licensing
    View All in Software Automation & Ground Systems →
    Software Over the Air: FatPipe Launches Acceleration Tool to Unclog Starlink and Amazon LEO LinksSoftware Over the Air: FatPipe Launches Acceleration Tool to Unclog Starlink and Amazon LEO Links
    Three LEO Operators Bet 2026 on a Supply Chain Built for 2027Three LEO Operators Bet 2026 on a Supply Chain Built for 2027
    NASA Advances Interoperable Space Networks with Successful PExT DemonstrationNASA Advances Interoperable Space Networks with Successful PExT Demonstration
    KSAT and iQPS Expand Strategic Alliance to Accelerate High-Frequency SAR ConstellationKSAT and iQPS Expand Strategic Alliance to Accelerate High-Frequency SAR Constellation
  • Services & Apps
    • Climate & Environmental Monitoring
    • Disaster Response & Security Mapping
    • Earth Observation & Imaging
    • Maritime & Aviation Satcom
    • Satellite Communications
    View All in Services & Applications →
    Eutelsat and Tototheo Global Forge Partnership to Deliver LEO Connectivity Across Maritime and Government SectorsEutelsat and Tototheo Global Forge Partnership to Deliver LEO Connectivity Across Maritime and Government Sectors
    Marlink Equips Groupama-FDJ Cycling Team with Hybrid Starlink and LTE NetworkMarlink Equips Groupama-FDJ Cycling Team with Hybrid Starlink and LTE Network
    Viasat Secures Lockheed Martin Contract for NOAA’s Next-Generation AircraftViasat Secures Lockheed Martin Contract for NOAA’s Next-Generation Aircraft
    SES Partners with Viva to Launch Multi-Orbit In-Flight ConnectivitySES Partners with Viva to Launch Multi-Orbit In-Flight Connectivity

ESA oversees on-orbit cybersecurity demo

May 7, 2023

Artistic rendition by ESA of their OPS-SAT satellite laboratory.

Under ESA’s supervision, a team of experts from Thales Alenia Space recently performed a cybersecurity demonstration that revealed they could covertly access parts of ESA’s OPS-SAT spacecraft that are usually off limits.

OPS-SAT is a flying laboratory which ESA offers to teams from across Europe to test innovative new software that is too risky to load on to normal operational satellites.

Once the Thales team successfully accessed the control layer of the satellite, they were able to demonstrate how they could tamper with images taken with the satellite’s camera and rotate the spacecraft away from its normal pointing.

What happened?
The demonstration was devised by cybersecurity company CYSEC, ESA and Thales. The Thales team then set to work devising a way to upload software to OPS-SAT that looked ‘harmless’ but it actually introduced a vulnerability that they would later exploit. By exploiting this vulnerability at a later time, they successfully accessed the control layer of the software, which is usually off limits for the experimenters.

The software and procedures were first tested on an identical copy of the satellite kept at ESA’s ESOC mission control center. This ensured that it could not do any irrecoverable damage to the satellite before it was installed on board.

Once they gained access to the control layer, the team was then able to replace an image taken with OPS-SAT’s camera and rotate the spacecraft away from the direction it was supposed to be pointing (they changed the satellite’s ‘attitude’).

“The ESA team then recovered the satellite and successfully reverted its software to a previous, safe and secure state,” said Simon Plum, Head of ESA Mission Operations. “This was a well-controlled experiment, in which ESA knew in advance what was going to happen, supervised the tests and retained control throughout the demonstration. The test was done in full isolation from ESA’s operational missions and enabled us to learn even more about possible cyber threats. Thanks to OPS-SAT, our teams across ESA and to the activity’s participants and organizers, such as CYSEC and Thales, we can now further enhance the security of operations at ESOC.”

What was the purpose of the demonstration
Every activity that humankind carries out using computers and other digital systems is exposed to cybersecurity threats. As satellites have become essential for so much of our daily lives, we must ensure they are as secure as possible.

“Spacecraft designers and operators need to understand how potential cyber attackers think. Only then can they build the best possible defence,” said David Evans, OPS-SAT project manager. “Activities like the one carried out by ESA and Thales are often referred to as ‘ethical hacking’ and they are a very effective way for spacecraft engineers to get this knowledge. Watching these attackers work and understanding their methodology was very valuable for us.”

This controlled experiment was an educational exercise and demonstrated the value in having cybersecurity experts with an offensive mindset involved in the development of satellite systems. The OPS-SAT team learned a lot from the experiment and, together with the Thales team and ESA’s Security Office, have used the results of the demonstration to update the security system at OPS-SAT’s SMILE control center.

The method of tampering with the spacecraft highlighted by the Thales team is no longer possible – one less potential path of attack for a real threat. Are other satellites at risk?

OPS-SAT is unique. Its role as a platform for experimentation and innovation means teams external to ESA are allowed to execute software on board the spacecraft. No other ESA satellite operates in this way.

The Thales team also had advanced access to information about OPS-SAT’s inner workings and were allowed to carry out tests on OPS-SAT’s flat sat as part of the cooperation.

OPS-SAT’s ground-based IT systems are isolated from those of any other ESA satellite, so the Thales team and other OPS-SAT experimenters cannot gain access to any other satellite systems.

Was OPS-SAT damaged?
OPS-SAT is designed to ensure it can always be reset to a safe state — in case even a well-meaning experiment causes any unexpected and potentially harmful effects. It also has an in-built system to monitor the satellite’s health and prevent it from becoming irrecoverable.

This cybersecurity experiment was performed entirely within OPS-SAT’s ‘random access memory’ (RAM). This computer memory was completely reset after the demonstration ensuring that any compromised software was removed, and the satellite returned to a known state.

No damage was done to OPS-SAT. OPS-SAT at Europe’s largest cybersecurity conference for the space sector

ESA and the Thales team presented the results of the cybersecurity demonstration at the CYSAT 2023 conference. The yearly event, organized by CYSEC, brings together the European space community to raise awareness of cybersecurity threats to space assets and how we can safeguard the important services they provide.

Filed Under: Government & Regulation, Spacecraft & Payload Technology

Primary Sidebar

Coverage

  • Missions & Constellations
  • Business & Finance
  • Military & Defense
  • Launch
  • Software Automation & Ground Systems
  • Government & Regulation
  • Services & Applications

Most Read Stories

  • SpaceX Debuts Starship V3: Redefining Heavy-Lift Launch Capability
  • SpaceX Is Worth $1.75 Trillion. Only 7% of That Is Real.
  • SpaceX: 10,000 Launches Annually
  • American military space closed around one company in seven days
  • The end of GEO?

Secondary Sidebar

Footer

 

Satnews is a leading provider of satellite news, events, publications, research and other satellite industry information in both commercial and military enterprises worldwide.

Stories By Category

  • Business & Finance
  • Government & Regulation
  • Launch
  • Military & Defense
  • Missions & Constellations
  • Services & Applications
  • Software Automation & Ground Systems
  • Spectrum & Licensing
  • Startups & NewSpace Business

About Us

  • Leadership & Editorial Team
  • SatNews History
  • Free Satnews Subscription
  • SatNews Events
  • Magazines

Navigation

  • Latest Stories
  • Magazines
  • Events
  • Contact
  • Cookie & Privacy Policy for Satnews

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.
x
Sign up Now (For Free)
Access daily or weekly satellite news updates covering all aspects of the commercial and military satellite industry.
Invalid email address
Notify Me Regarding ( At least one ):
We value your privacy and will not sell or share your email or other information with any other company. You may also unsubscribe at anytime.

Click Here to see our full privacy policy.
Thanks for subscribing!