Securing Space: The Next Frontier for Security Engineers
Anshu Gupta
BSidesSF 2026 · Day 1 · AMC Theatre 04
Overview
Anshu Gupta's talk, "Securing Space: The Next Frontier for Security Engineers," delivered at BSides SF, serves as a clarion call for security professionals to turn their attention to the rapidly evolving and increasingly vulnerable space sector. Gupta emphasizes that space, once the exclusive domain of governments, is now a burgeoning commercial frontier, with a massive influx of startups and significant investments from Fortune 500 companies. This expansion, while promising technological advancement and economic growth, simultaneously introduces a complex array of cybersecurity challenges that demand immediate and innovative solutions.
Key moments
- 0:00 Introduction to securing space and its growing importance
- 1:30 Satellites are fundamental to modern civilization
- 2:30 Satellites are IoT devices in a highly contested domain
- 4:20 Launching a small satellite is surprisingly affordable (300K)
- 6:20 Huge opportunities and talent shortage in space tech
- 7:00 Existing security skills are transferable to new space roles
Securing Space: The Next Frontier for Security Engineers
Speakers: Anshu Gupta
Conference: BSides SF
YouTube: https://www.youtube.com/watch?v=ddSJ4KKFPJ8
Overview
Anshu Gupta's talk, "Securing Space: The Next Frontier for Security Engineers," delivered at BSides SF, serves as a clarion call for security professionals to turn their attention to the rapidly evolving and increasingly vulnerable space sector. Gupta emphasizes that space, once the exclusive domain of governments, is now a burgeoning commercial frontier, with a massive influx of startups and significant investments from Fortune 500 companies. This expansion, while promising technological advancement and economic growth, simultaneously introduces a complex array of cybersecurity challenges that demand immediate and innovative solutions.
The talk highlights the critical dependence of modern civilization on space infrastructure, from Positioning, Navigation, and Timing (PNT) services like GPS to global internet connectivity provided by constellations such as Starlink, and essential climate monitoring. Given this foundational role, the security of space assets is paramount. Gupta argues that the "highly contested domain" of space, likened to the geopolitical scramble for the Arctic, necessitates a proactive and robust security posture. The core message is clear: traditional security expertise is highly transferable to this new domain, and there is a massive talent shortage, presenting a unique opportunity for security engineers to make a significant impact on an emerging and vital industry.
Background
▶ Watch: Introduction to securing space and its growing importance (0:00)
The modern world's reliance on space assets is profound and often unseen. Our daily lives, critical infrastructure, and national security are inextricably linked to satellites providing PNT data, global internet access, climate monitoring, and earth observation. Gupta points out that satellites are, at their core, sophisticated IoT devices with solar panels, but operating in an environment far more hostile and contested than terrestrial IoT. Historically, space exploration and utilization were predominantly government-led endeavors by entities like NASA, supported by a few large contractors such as Boeing. However, this landscape has dramatically shifted.
Today, the commercial space sector is booming. Gupta notes that nearly every Fortune 500 company now has a "space strategy," and the barrier to entry for launching small satellites has plummeted. For example, a 50-kilogram satellite can be launched for approximately $300,000, making space accessible to startups and even high school projects. This commercialization is evidenced by the proliferation of Y Combinator-funded space startups (55 companies mentioned), exploring everything from mineral extraction on asteroids to space tourism and advanced data analytics. This rapid commercial growth, driven by venture capital, often prioritizes speed-to-market and product-market fit, leading to a "fail fast" mentality that, when applied to irrecoverable space assets, poses significant security risks.
The speaker highlights a critical talent shortage in space security, presenting a unique opportunity for existing security professionals. A cloud engineer can transition to a ground segment defender, an application security (appsec) engineer can become a flight software security expert, and a SOC analyst can evolve into an orbital anomaly hunter. The underlying principle is that much of space technology is "just code" and hardware, susceptible to the same vulnerabilities (e.g., buffer overflows) as terrestrial systems, but with far greater consequences and unique environmental challenges. The presence of legacy hardware and the difficulty of patching or physically accessing deployed satellites further exacerbate these security concerns. The talk also introduces the concept of Kessler Syndrome, where a single compromised or destroyed satellite could trigger a cascade of collisions, rendering specific orbits unusable for decades or centuries, underscoring the global stakes involved.
Key Findings
▶ Watch: Satellites are IoT devices in a highly contested domain (2:30)
Gupta's talk underscores several critical findings regarding the current state of space security, emphasizing both existing threats and emerging defensive strategies.
One of the most significant real-world examples cited is the Viasat (KA-SAT) attack that occurred approximately three years prior. This incident, attributed to Russia at the onset of the Ukrainian conflict, was not a direct hack of satellites but rather a supply chain attack targeting ground infrastructure. Malicious updates were sent to modems used by the KA-SAT network, effectively "frying" their flash memory. The AcidRain wiper malware used in the attack was identified by its family, previously associated with a specific Russian APT group, allowing for attribution. While primarily aimed at disrupting Ukrainian military command and control, the attack had widespread global impacts, affecting European residential customers, wind turbine monitoring systems in Germany, and even national security agencies worldwide. This event served as a stark demonstration of how vulnerabilities in the ground segment can have far-reaching, kinetic-like effects.
Another key finding revolves around Starlink's innovative anti-jamming capabilities in response to active jamming efforts, particularly in the Ukrainian conflict and Iran. Governments deployed high-powered, truck-mounted jammers capable of disrupting satellite terminals within a 20-30 mile radius. Starlink responded with both physical and programmatic countermeasures. Physically, users in Ukraine dug ditches or built enclosures around terminals to block horizontal jamming signals. Programmatically, Starlink implemented real-time updates that enabled terminals to sense intense jamming signals and create "blind spots," refusing to accept high-frequency interference from specific directions. This adaptive null steering antenna technique, combined with multi-antenna systems that analyze signal arrival angles, showcased a rapid, software-defined response to electronic warfare. Crucially, this was achieved via Over-The-Air (OTA) updates, highlighting the importance of agile software deployment in space.
The speaker also revealed that Deloitte has partnered with Spire Global to launch nine satellites, specifically for testing a "silent shield" threat monitoring solution designed to detect intrusions. While currently a testbed, this initiative signifies a growing commercial interest in developing dedicated space security services.
A significant systemic vulnerability identified is the lack of encryption and replay protection in many satellite command functions. Gupta explicitly states that commands given to non-stationary objects (satellites with thrusters) often lack these fundamental security controls, making them susceptible to manipulation or replay attacks. This is a critical gap, particularly given that satellites are expensive, difficult-to-retrieve assets.
Finally, the talk highlights the low adoption rate of the Space Data Link Security Protocol (SDLS), despite its intention to serve as the "IPsec for space." The primary hurdles are the high overhead associated with authentication and encryption, which demands significant compute resources and memory – commodities that are scarce in the constrained environments of small, power-limited satellites. This trade-off between security and operational efficiency remains a major challenge.
Technical Deep Dive
▶ Watch: Launching a small satellite is surprisingly affordable (300K) (4:20)
Securing space systems requires a comprehensive understanding of their unique architecture and the specific threats they face. Anshu Gupta breaks down the space ecosystem into four primary segments, each with distinct security considerations:
- Space Segment: This encompasses everything beyond Earth's atmosphere, including satellites, rovers (e.g., on Mars or the Moon), and space stations. Satellites are often described as IoT devices with solar panels, running on C/C++ (even for SpaceX, though Python is used for less performance-critical tasks). The challenge here is the extreme operating environment (radiation, solar flares) necessitating rugged hardware, and the difficulty of physical access for patching or updates once deployed.
- Ground Segment: This consists of Earth-based infrastructure, including large parabolic antennas, mission control centers, and data processing facilities. Companies like Amazon Web Services (AWS) offer "Ground Station as a Service," positioning ground stations next to their data centers to minimize latency. Microsoft Azure Orbital also provides similar services, though focusing more on data processing rather than physical infrastructure. Securing these terrestrial components, which have physical access points and traditional network attack surfaces, is critical as demonstrated by the Viasat attack.
- Link Segment: This refers to the communication pathways between segments.
- Uplink: Data or commands sent from the ground to a satellite.
- Downlink: Data transmitted from a satellite to the ground.
- Crosslink: Communication between two satellites, common in modern constellations like Starlink, enabling mesh networks in space with dynamic handoffs as satellites move across the sky.
Gupta notes a significant vulnerability in command functions: a frequent lack of encryption and replay protection in these links, allowing for potential manipulation or retransmission of sensitive commands.
- User Segment: This includes end-user devices such as satellite modems, phones, and handsets that interact with the satellite network.
Key Concepts and Threats:
- GPS vs. GNSS: GPS (Global Positioning System) is specifically the US government-owned (military) system, while GNSS (Global Navigation Satellite Systems) is the umbrella term for all global navigation systems, including GPS, Russia's GLONASS, Europe's Galileo, and China's BeiDou.
- Jamming: An electronic warfare technique where high-power radio signals overwhelm legitimate satellite signals, effectively "drowning them out." This is relatively easy to implement. Countermeasures include physical enclosures, digging ditches (as seen in Ukraine), spatial filtering (using multiple antennas to discern signal origin), and null steering antennas (creating "blind spots" to ignore jamming signals, as implemented by Starlink via OTA updates).
- Spoofing: A more sophisticated attack where an adversary mimics legitimate satellite signals to manipulate a receiver's PNT data. This is currently an active threat, particularly in the Middle East, causing ships' clocks to rotate erratically. Spoofing is harder than jamming as it requires precise emulation of a device's transmission characteristics.
- TTC (Telemetry, Tracking, and Command): These are the signals used to monitor the satellite's health (telemetry), track its position (tracking), and issue operational directives (command). As mentioned, the command function often lacks encryption and replay protection, making it a prime target.
Protocols and Standards:
The Consultative Committee for Space Data Systems (CCSDS) is the international body responsible for developing space communication standards, akin to ISO or NIST for terrestrial networks. They have developed protocols like the Space Packet Protocol, Advanced Orbiting Systems, and the Unified Space Link Protocol (USLP), which mirror layers of the OSI model.
Recognizing historical security oversights (similar to early internet protocols), CCSDS introduced the Space Data Link Security Protocol (SDLS), updated as recently as July 2022. SDLS aims to be the "IPsec for space," providing authentication and encryption. However, its adoption is low due to the high computational and memory overhead required, which is challenging for resource-constrained satellites and can introduce unacceptable latency.
Threat Modeling with SPARTA:
For traditional appsec, the STRIDE model (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege) is common. However, for space systems, a new framework called SPARTA (Space Attack Research and TTP Analysis) is gaining traction. Developed by the Aerospace Corporation (a government-owned non-profit, original creators of GPS), SPARTA provides a detailed, unclassified framework akin to the MITRE ATT&CK framework. It includes unique space-specific threats and techniques such as:
- Orbital maneuvering: Can an adversary stop or manipulate a satellite's movement?
- RF Recon: Radio frequency reconnaissance to intercept telemetry or sensitive data.
- Telemetry analysis: Inferring information from a satellite's operational data.
- Protocol fuzzing: Testing for vulnerabilities in communication protocols.
- Uplink abuse: Sending malicious commands via unencrypted uplinks to cause depletion of fuel or redirection.
- Supply chain insertion: A long-term nation-state strategy to inject malicious components during manufacturing.
Defensive Strategies and Tools:
- Hardware Security: Implementing Hardware Security Modules (HSMs), secure enclaves, root of trust, and using ephemeral keys to limit the impact of compromise. The challenge of rotating credentials for moving satellites is noted.
- Resilient Communications: Techniques like frequency hopping and spread spectrum to make signals harder to jam or intercept.
- Incident Response: Complex in space due to physical inaccessibility and the need to differentiate between natural phenomena (radiation, solar flares) and malicious attacks. Involves ground station health checks, side-channel data analysis, and remote recovery modes.
- AI in Space: Leveraging AI for onboard anomaly detection and autonomous response to attacks, effectively creating an "on-orbit security officer" to mitigate threats faster than ground-based human intervention.
- Open Source & DIY: The barrier to entry for space security research is lowered by tools like Software-Defined Radios (SDRs) (e.g., RTL-SDR for $47), and software such as GNU Radio, SAT dump, and DragonOS. These allow enthusiasts to sniff and analyze space traffic. CubeSats (10x10x10cm satellites) are also becoming popular DIY projects, though their low security makes them potential vectors for malicious activities.
Demo / Proof of Concept
▶ Watch: Huge opportunities and talent shortage in space tech (6:20)
While Anshu Gupta's talk did not feature a live, interactive demonstration in the traditional sense, it highlighted several accessible tools and concepts that enable practical engagement with space security, effectively serving as a guide for self-directed proof-of-concept work.
Gupta specifically mentioned Software-Defined Radios (SDRs) as a low-cost entry point for aspiring space security researchers. He stated that an SDR kit could be acquired for as little as $47-$48, allowing individuals to start "tinkering and trying to figure this stuff out." This hardware, combined with open-source software like GNU Radio, SAT dump, and DragonOS, forms a powerful toolkit.
A screenshot from SAT dump was presented, illustrating how over-the-air satellite data can be captured, graphed, and visualized. The image showed a "beautiful" overlay of Earth, demonstrating the ability to "sniff" and analyze space traffic much like network traffic is analyzed with tools like Wireshark. This capability allows researchers to understand satellite communication protocols, identify potential vulnerabilities, and even monitor legitimate and anomalous transmissions.
Furthermore, the talk touched upon CubeSats – small, modular satellites (typically 10x10x10 cm) that have become popular projects for high school students and hobbyists due to their relatively low cost and ease of deployment. Gupta described them as "very cool projects" but also cautioned that "since they're small, they don't have security and they can be used to do bad things." This implicitly positions CubeSats as a potential platform for demonstrating both benign and malicious payloads or communication techniques in orbit, serving as a real-world, albeit simplified, proof-of-concept environment for space-based operations.
These examples collectively illustrate that hands-on experimentation in space security is not confined to government labs or multi-million dollar facilities, but can begin with accessible, off-the-shelf hardware and open-source software, making the field approachable for a wider audience of security enthusiasts.
Defensive Implications
▶ Watch: Existing security skills are transferable to new space roles (7:00)
The burgeoning commercial space sector, coupled with persistent nation-state threats, necessitates a robust and multi-layered defensive strategy. Anshu Gupta outlined several critical areas where security professionals must focus their efforts:
- Secure the Ground Segment: The Viasat attack demonstrated that the ground segment is a prime vulnerability. Defenders must prioritize physical security for ground stations and mission control centers, implement stringent patching and update management for all software and firmware, and apply traditional cybersecurity controls such as network segmentation, strong authentication, and continuous monitoring. Cloud engineers transitioning to this role will find their skills directly applicable here, securing AWS Ground Station or Azure Orbital instances.
- Encrypt and Authenticate the Link Segment: The current lack of encryption and replay protection in many satellite command uplinks is a critical vulnerability. It is imperative to enforce end-to-end encryption for all uplink, downlink, and crosslink communications. Protocols like SDLS (Space Data Link Security Protocol), despite their computational overhead, must be adopted where feasible, or lighter-weight, high-assurance alternatives developed. Replay protection mechanisms are also essential to prevent malicious retransmission of commands.
- Harden the Space Segment: Satellites themselves must be designed with security in mind from the outset, embracing a zero-trust architecture. This includes implementing Hardware Security Modules (HSMs), secure enclaves, and establishing a root of trust for all onboard systems. Ephemeral keys and robust key rotation mechanisms are crucial, despite the challenges posed by moving objects and limited communication windows. Flight software must be developed with secure coding practices, undergoing rigorous vulnerability testing for issues like buffer overflows.
- Implement Resilient Communications: To counter jamming and spoofing, space systems need inherent resilience. This involves techniques like frequency hopping and spread spectrum to make signals harder to disrupt. Spatial filtering using multiple antennas and null steering antennas (as demonstrated by Starlink) can dynamically mitigate jamming. The ability to push Over-The-Air (OTA) updates for security patches and anti-jamming capabilities is vital for adapting to evolving threats.
- Proactive Threat Modeling with SPARTA: Security teams must move beyond traditional appsec models like STRIDE and adopt space-specific frameworks such as SPARTA (Space Attack Research and TTP Analysis). This allows for a comprehensive understanding of unique threats like orbital maneuvering manipulation, RF reconnaissance, and supply chain insertion, enabling the development of targeted countermeasures.
- Develop Robust Incident Response (IR) for Space: Given the physical inaccessibility and extreme environment of space assets, IR processes must be tailored. This includes distinguishing between natural phenomena (e.g., radiation effects) and malicious activity, leveraging side-channel data analysis for troubleshooting, and developing reliable remote recovery modes (the "space version of a restart"). The inherent slowness of IR in space emphasizes the need for preventative measures.
- Leverage AI for Onboard Security: Artificial intelligence offers a promising avenue for enhancing space security. Onboard anomaly detection can identify suspicious behavior on the satellite itself, reducing reliance on ground-based monitoring and its associated latency. Autonomous response capabilities, where pre-defined runbooks are embedded in the device, can enable rapid mitigation of attacks without human intervention, effectively creating an "on-orbit security officer."
- Address Supply Chain Security: The long-term nature of space projects makes them vulnerable to nation-state supply chain attacks. Defenders must implement rigorous vetting of hardware and software components, from design to manufacturing, to prevent the insertion of malicious chips or backdoors.
- Engage with Standards and Regulations: Security professionals should actively engage with and implement guidelines from bodies like NIST (e.g., "Cybersecurity for Commercial Satellite Operations," "Framework for PNT Services"), CCSDS, and reports from organizations like the European Space Agency (ESA) on threat landscapes and control frameworks. Participation in ISACs (Information Sharing and Analysis Centers), such as the US Space ISAC and the newly formed EU Space ISAC, is crucial for intelligence sharing and collaborative defense.
By focusing on these areas, security engineers can help ensure the safety, resilience, and integrity of humanity's growing presence in space, transforming their existing skills into a new, impactful frontier.
Key Takeaways
- Space is a Critical and Contested Domain: Modern civilization relies heavily on space assets for PNT, communication, and observation. This makes space a highly contested domain, with nation-state and commercial interests creating unique and severe cybersecurity risks.
- Traditional Security Skills are Transferable but Require Adaptation: Cloud, appsec, and SOC analysis skills are directly applicable to space security, but require understanding the unique taxonomy (space, ground, link, user segments) and specific threats (jamming, spoofing, orbital maneuvering). New threat modeling frameworks like SPARTA are essential.
- Vulnerabilities Span All Segments with Global Impact: Attacks like the Viasat incident demonstrate that vulnerabilities in ground infrastructure can have widespread, kinetic-like effects. The lack of encryption and replay protection in command links, and the challenges of securing legacy hardware or resource-constrained CubeSats, present significant attack surfaces.
- Security Must Be Built-in, Not Bolted-on: The "fail fast" mentality of commercial startups is dangerous for irrecoverable space assets. Robust hardware security modules, zero-trust architectures, and secure coding practices are paramount from the design phase, emphasizing prevention over costly and slow incident response.
- Innovation in Defense is Crucial: Adaptive countermeasures like Starlink's null steering antennas (via OTA updates) and the potential of AI for onboard anomaly detection and autonomous response highlight the need for continuous innovation in defensive strategies against evolving threats.
- Open Source and Community Drive Accessibility: Low-cost Software-Defined Radios (SDRs) and open-source tools like GNU Radio and SAT dump are democratizing space security research, lowering the barrier to entry and fostering a vibrant community for learning and experimentation.
About the Speaker(s)
Anshu Gupta is an enthusiastic and passionate advocate for space security. Based on his presentation, he is deeply excited about the potential and challenges of securing humanity's presence beyond Earth, aiming to educate and inspire others to join this emerging field. He actively encourages networking and discussion on the topic, notably through his LinkedIn presence, where he shares insights and engages with the community. His background appears to encompass extensive experience in traditional cybersecurity, which he adeptly applies to the novel context of space systems, having worked for "two of the big four firms, Anson Young and KPMG."
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
A competent survey-level introduction to space security that covers the terrain honestly — SPARTA, SDLS, the Viasat post-mortem, jamming countermeasures — without delivering anything a motivated researcher couldn't assemble from public sources in an afternoon. It's a good onboarding talk for security generalists eyeing a career pivot, but it doesn't advance the field.
Heather Calloway (CISO) — SOLID
A competent orientation to space security that covers the terrain without breaking new ground. Gupta clearly knows the domain and the Viasat case lands, but this is a recruitment and awareness talk, not a governance or operator decision brief — and it doesn't pretend otherwise.