{"id":48028,"date":"2025-11-18T17:36:25","date_gmt":"2025-11-18T09:36:25","guid":{"rendered":"https:\/\/wp-productionenv-bjg9h2g2bgg5b8aa.southeastasia-01.azurewebsites.net\/news\/multi-orbit-networks-expand-the-attack-surface-but-basic-cyber-threats-remain-experts-say\/"},"modified":"2025-11-18T17:36:25","modified_gmt":"2025-11-18T09:36:25","slug":"multi-orbit-networks-expand-the-attack-surface-but-basic-cyber-threats-remain-experts-say","status":"publish","type":"post","link":"https:\/\/starpath.global\/news\/multi-orbit-networks-expand-the-attack-surface-but-basic-cyber-threats-remain-experts-say\/","title":{"rendered":"Multi-Orbit Networks Expand the Attack Surface, But Basic Cyber Threats Remain, Experts Say"},"content":{"rendered":"<\/p>\n<p><em>RESTON, Virginia<\/em> \u2014 Software-defined satellites and multi-orbit architecture open up an expanded attack surface for hackers, but those vulnerabilities remain largely theoretical for now, satellite cyber and engineering experts said Monday during CyberSat. The real and present dangers lie in more low hanging fruit, they said.<\/p>\n<p>Five years ago, a presentation by James Pavur at the Black Hat cybersecurity conference sent shockwaves through the satellite industry, when he revealed how trivially easy it was to eavesdrop on unencrypted satellite downlinks.<\/p>\n<p>This month,&nbsp;the University of California San Diego and the University of Maryland published a study recently covered by Wired, which found that \u201croughly half\u201d of the traffic from Geostationary Orbit (GEO) satellites is still unencrypted.<\/p>\n<p>\u201cIt just blew my mind,\u201d said Norm Laudermilch, CISO of Vantor.<\/p>\n<p>\u201cFive years later, we\u2019re doing the exact same thing, not encrypting the downlink,\u201d added Brandon Bailey, a cybersecurity expert with the federally funded research organization Aerospace Corp. \u201cI don\u2019t even know how we\u2019re at this stage in the game,\u201d he said.<\/p>\n<p>Scott McCormick, CSO of Planet, pointed out that&nbsp;the study looked exclusively at older GEO satellites. \u201cThere\u2019s assets on that list [in the study] that were quite aged and it was a bit skewed.\u201d Nonetheless, he added \u201cencryption is a must.\u201d<\/p>\n<p>In a separate&nbsp;presentation, Jason McCollum, the vice president for Software &amp; Security at Comtech said that \u201clegacy&nbsp;thinking\u201d is even more widespread than legacy technology.<\/p>\n<p>Legacy thinking on the encryption and authentication issue, McCollum said, includes the idea that \u201cIt\u2019s too hard for an attacker to figure out proprietary protocols. \u2026&nbsp; That\u2019s never been true. It\u2019s not too hard to reverse engineer proprietary protocols.\u201d<\/p>\n<p>Another example of legacy thinking is that no one is asking for different behavior. While that\u2019s \u201coften true,\u201d he said, it doesn\u2019t account for the fact that customers frequently do not understand the consequences of eschewing encryption.<\/p>\n<p>In addition to eavesdropping and packet sniffing of unencrypted downlinks, Bailey said, data compiled by Aerospace Corp. showed that other \u201cbare minimum, basic\u201d&nbsp;attacks, like radio frequency (RF) jamming are the most prevalent.<\/p>\n<p>Industry standard encryption and authentication technologies could help mitigate such attacks, Bailey said. But he added that encryption could be defeated on the ground if networks aren\u2019t protected. \u201cWe have too much trust built into our architectures, into that trusted link between the ground and the spacecraft,\u201d he said, pointing out that in the penetration testing work Aerospace did on live systems, \u201cWe abuse that trust continuously.\u201d<\/p>\n<h3>Supply Chain Risks<\/h3>\n<p>Beyond the attack surface of the satellite operators\u2019 own systems, panelists explained, lays the vast and often dark terrain of their supply chain.<\/p>\n<p>\u201cThe satellite supply chain is global. It\u2019s incredibly complex and very often opaque, and every subsystem, from attitude control to the RF components, comes from a different source, and each of those sources introduces its own potential risk to the overall system,\u201d said Laudermilch.<\/p>\n<p>Even something as simple as a list of suppliers might be difficult to compile, said Matt McClung, director of Cyber Engineering for satellite manufacturer Lanteris Space Systems.<\/p>\n<p>\u201cYou have to start with a comprehensive list of all your suppliers, and understand what they\u2019re providing to the company: software, hardware, services,\u201d he said. But companies also have to understand their suppliers\u2019 suppliers, so-called fourth party risk.<\/p>\n<p>\u201cOnce you have that list, then you can start building a view of what\u2019s the risk associated with each of them,\u201d he said. Software and hardware had to be dealt with differently, he explained, \u201cYou can\u2019t treat all the suppliers the same.\u201d<\/p>\n<p>McClung said that the sheer volume of data points about so many companies sometimes makes an automated platform a good investment.<\/p>\n<p>Assessing supply chain risk means evaluating the trade-offs in \u201cbuy versus build,\u201d McCormick said. \u201cWe build most of ours,\u201d he said, \u201cSo we own it through the whole pipeline. But if you are going to go out and use AWS ground stations, or whoever, obviously understanding the risks and tradeoffs is key.\u201d<\/p>\n<p>\u201cI think we\u2019re all in that boat,\u201d added Laudermilch. \u201cWe\u2019re all using commercial services at some level.\u201d<\/p>\n<h3>Threats in Multiple Orbits<\/h3>\n<p>The growth of multi-orbit architectures and the integration of multiple terrestrial networks raises new security risks, explained Vinit Duggal, CISO and vice president for Network Engineering of European operator SES. He described SES\u2019s&nbsp;satellites as \u201crouters in the sky,\u201d connecting different constellations and different networks.<\/p>\n<p>SES this year completed its acquisition of Intelsat, and the company also has a partnership with OneWeb, so being able to track traffic across different networks and constellations and know it is protected from end-to-end is critical, he said. Each handle security slightly differently, \u201cThere\u2019s no one right answer. Everybody\u2019s handwriting is a little bit different,\u201d he said.<\/p>\n<p>\u201cFor us, it\u2019s around visibility, bringing it back to one funnel, so we can apply the right security to the traffic. \u2026 That integration is extremely important. It\u2019s something we\u2019re paying a lot of attention to,\u201d Duggal said.<\/p>\n<p>Duggal added that SES is not seeing any attacks on, or attempts to take over, its actual spacecraft. \u201cWe are not seeing any direct command intrusion [or] command spoofing, activity on our assets,\u201d he said. Crediting the company\u2019s use of encryption and a security technique known as \u201ccommand lock\u201d under which the satellite will not accept certain kinds of instructions.<\/p>\n<p>Bailey, however, pointed out that very high end attacks like those on spacecraft may not be happening at the moment but with increasing strategic competition in the space domain, that isn\u2019t likely to be the case for much longer.<\/p>\n<p>\u201cYour company, probably like others, aren\u2019t seeing a lot of action on the platform itself yet,\u201d Bailey warned, \u201cBut we anticipate that changing.\u201d<\/p>\n<p><strong>More from CyberSat 2025:&nbsp;<\/strong><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\">NRO Establishes Space Cyber Program After Last Month\u2019s Moonshine Guardian Exercise<\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\">DHS Wants Satellite Volunteers to Test New Cyber Tools<\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\">Pentagon\u2019s Acting CIO Arrington Pushes Against Complacency in Space Cybersecurity<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>RESTON, Virginia \u2014 Software-defined satellites and multi-orbit architecture open up an expanded attack surface for hackers, but those vulnerabilities remain largely theoretical for now, satellite cyber and engineering experts said Monday during CyberSat. The real and present dangers lie in more low hanging fruit, they said. Five years ago, a presentation by James Pavur at [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":48029,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":"","_links_to":"","_links_to_target":""},"categories":[2],"tags":[],"class_list":["post-48028","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"acf":[],"_links":{"self":[{"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/posts\/48028"}],"collection":[{"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/comments?post=48028"}],"version-history":[{"count":0,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/posts\/48028\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/media\/48029"}],"wp:attachment":[{"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/media?parent=48028"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/categories?post=48028"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/tags?post=48028"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}