{"id":61040,"date":"2019-11-22T22:31:44","date_gmt":"2019-11-22T14:31:44","guid":{"rendered":"https:\/\/wp-productionenv-bjg9h2g2bgg5b8aa.southeastasia-01.azurewebsites.net\/news\/satellite-cybersecurity-beset-by-misaligned-market-incentives\/"},"modified":"2019-11-22T22:31:44","modified_gmt":"2019-11-22T14:31:44","slug":"satellite-cybersecurity-beset-by-misaligned-market-incentives","status":"publish","type":"post","link":"https:\/\/starpath.global\/news\/satellite-cybersecurity-beset-by-misaligned-market-incentives\/","title":{"rendered":"Satellite Cybersecurity Beset by Misaligned Market Incentives"},"content":{"rendered":"<\/p>\n<p>Many things make cybersecurity for the satellite sector difficult: IT in space is tough to update and satellite systems are enormously complex. But the hardest thing of all might be that market incentives are misaligned, panelists said at CyberSat 2019.<\/p>\n<p>The satellite sector \u2014 like other critical industry verticals \u2014 is under constant cyber attack, probed by nation-state hackers set on ensuring they can degrade US space capabilities in order to cripple its economy or defeat its military when they need to, industry executives told a panel on \u201cemerging threats to the satellite sector.\u201d<\/p>\n<p>Cybersecurity is costly and the incentive structure in the industry often doesn\u2019t reward investments in it, said Andrew D\u2019Uva, president of the Providence Access Company, a communication satellite services firm.<\/p>\n<p>\u201cThe biggest threat, in my mind, to cybersecurity in commercial space systems is capitalism,\u201d he said, \u201cCapitalism values efficiency above everything else\u201d and the correct incentives had not been applied.<\/p>\n<p>When it came to satellite communications services, \u201cThe government doesn\u2019t value in most cases effective cybersecurity,\u201d he said. \u201cThey allow industry to self-certify, self-assess and&nbsp; \u2026 in the commercial satcom area at least, they haven\u2019t bothered to check the effectiveness of those controls.<\/p>\n<p>\u201cIt\u2019s a paper game,\u201d he added, meaning those who make real investments in security suffer smaller profit margins than those who merely do the minimum needed to tick the box.<\/p>\n<p>As a result, in many companies in the sector, \u201ccybersecurity is not baked in, it\u2019s a bolt on, add in kind of a thing,\u201d he said.<\/p>\n<p>Satellite systems are enormously complex, he told Via Satellite Magazine after the panel. Each segment \u2014 the ground stations, the space vehicles, the user terminals \u2014 was in itself a full-scale IT system, and each was interconnected with the others.<\/p>\n<p>\u201cThe complexity, that\u2019s the hard part\u201d when it comes to cybersecurity, he said.<\/p>\n<p>Satellite systems also encompass both commodity IT alongside esoteric legacy space systems, some of which have been on orbit for decades.<\/p>\n<p>\u201cYou can patch a circuit board,\u201d D\u2019Uva said. \u201cThese (legacy) satellites were designed to be \u2018set it and forget it,\u2019 \u2026 To be beyond the reach of human hands for 15 or 20 years \u2026 That has to end \u2026 It has to be updateable.\u201d<\/p>\n<p>A&nbsp;new generation of software-defined satellite systems was already arriving, panelists said.<\/p>\n<p>Amazon was now offering \u201cground station as a service\u201d \u2014 a virtual ground station in the cloud \u2014 said Mari Spina, principal cybersecurity engineer for the MITRE Corp., a federally-funded non profit research association.<\/p>\n<p>This fusion of satellite and more conventional IT like the cloud meant there would be \u201cVulnerabilities coming out of the IT sector,\u201d for satellite systems, she said.<\/p>\n<p>Spina is also the cloud security capability leader for MITRE and warned that the shared responsibility for security implied by cloud computing \u201cis making everyone hiccup,\u201d as they adjusted to the new model.<\/p>\n<p>\u201cYou have to trust your cloud service provider,\u201d she explained. \u201cYou have to trust their controls. You can\u2019t see those controls, the providers don\u2019t want to let you look under the hood.\u201d<\/p>\n<p>Third-party certifications like FedRAMP could help ensure that you can trust those cloud provider controls, but satellite companies should still consider putting their own security stack in the cloud, Spina told Via Satellite Magazine after the panel. She cited the Defense Information Systems Agency\u2019s Secure Cloud Computing Architecture (SCCA) as a model.<\/p>\n<p>\u201cSSCA protects you like you\u2019re in your own data center,\u201d she said.<\/p>\n<p>The increased use of conventional IT would also enable the space sector to leverage improvements to cybersecurity that terrestrial sectors had been working on for years, she said, adding that the CVE system and the the ATT&amp;K framework \u2014 two widely used cybersecurity tools developed by MITRE \u2014 were being updated to incorporate cloud based vulnerabilities and attacks.<\/p>\n<p>Another concern, she said, was that the industry really needed to ensure it had visibility and security throughout its supply chain. \u201cIs what\u2019s going into orbit what you think is going into orbit?\u201d she asked. \u201cI would beg you, inspect your hardware \u2026 The quickest way to cross an air gap is through your supply chain.\u201d<\/p>\n<p>The attitude she heard frequently was \u201cWe can\u2019t inspect everything,\u201d she said, but that doesn\u2019t mean they shouldn\u2019t bother. \u201cYou can do some level setting \u2026 If you\u2019re not looking, you can\u2019t see it\u201d at all.<\/p>\n<p>And it wasn\u2019t just a hardware issue, she added, \u201cThere\u2019s a tremendous number of software components going into \u2026 the overall software stack.\u201d<\/p>\n<p>The scale of the problem might seem overwhelming, concluded, D\u2019Uva, but it was important not to be discouraged. \u201cThis is a big elephant, we have to eat it piece by piece,\u201d he said.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Many things make cybersecurity for the satellite sector difficult: IT in space is tough to update and satellite systems are enormously complex. But the hardest thing of all might be that market incentives are misaligned, panelists said at CyberSat 2019. The satellite sector \u2014 like other critical industry verticals \u2014 is under constant cyber attack, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":61042,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":"","_links_to":"","_links_to_target":""},"categories":[2],"tags":[],"class_list":["post-61040","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"acf":[],"_links":{"self":[{"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/posts\/61040"}],"collection":[{"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/comments?post=61040"}],"version-history":[{"count":0,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/posts\/61040\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/media\/61042"}],"wp:attachment":[{"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/media?parent=61040"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/categories?post=61040"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/tags?post=61040"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}